CVE-2023-27602
published 2023-04-10CVE-2023-27602: In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users…
PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.00%
78.4th percentile
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
We recommend users upgrade the version of Linkis to version 1.3.2.
For versions
<=1.3.1, we suggest turning on the file path check switch in linkis.properties
`wds.linkis.workspace.filesystem.owner.check=true`
`wds.linkis.workspace.filesystem.path.check=true`
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | linkis | <= 1.3.1 | — |
| apache_software_foundation | apache_linkis | <= 1.3.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Linkis Unrestricted File Upload vulnerability
osv·2023-07-06
CVE-2023-27602 [CRITICAL] Apache Linkis Unrestricted File Upload vulnerability
Apache Linkis Unrestricted File Upload vulnerability
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
We recommend users upgrade the version of Linkis to version 1.3.2.
For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties
`wds.linkis.workspace.filesystem.owner.check=true`
`wds.linkis.workspace.filesystem.path.check=true`
GHSA
Apache Linkis Unrestricted File Upload vulnerability
ghsa·2023-07-06
CVE-2023-27602 [CRITICAL] CWE-434 Apache Linkis Unrestricted File Upload vulnerability
Apache Linkis Unrestricted File Upload vulnerability
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
We recommend users upgrade the version of Linkis to version 1.3.2.
For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties
`wds.linkis.workspace.filesystem.owner.check=true`
`wds.linkis.workspace.filesystem.path.check=true`
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/04/10/1http://www.openwall.com/lists/oss-security/2023/04/18/4http://www.openwall.com/lists/oss-security/2023/04/19/3https://lists.apache.org/thread/wt70jfc0yfs6s5g0wg5dr5klnc48nsp1http://www.openwall.com/lists/oss-security/2023/04/10/1http://www.openwall.com/lists/oss-security/2023/04/18/4http://www.openwall.com/lists/oss-security/2023/04/19/3https://lists.apache.org/thread/wt70jfc0yfs6s5g0wg5dr5klnc48nsp1
2023-04-10
Published