CVE-2023-50740

Severity
5.3MEDIUM
EPSS
0.2%
top 62.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6

Description

In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. We recommend users upgrade the version of Linkis to version 1.5.0

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

3
CVEList
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged2024-03-06
OSV
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged2024-03-06
GHSA
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged2024-03-06
CVE-2023-50740 (MEDIUM CVSS 5.3) | In Apache Linkis <=1.4.0 | cvebase.io