漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Linkis (incubating): The DatasourceManager module has a serialization attack vulnerability
Vulnerability Description
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and malicious parameters. Therefore, the parameters in the jdbc url should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users to upgrade the version of Linkis to version 1.3.1.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Apache Linkis 代码问题漏洞
Vulnerability Description
Apache Linkis是美国阿帕奇(Apache)基金会的一款中间件产品,可以在上层应用和底层数据引擎之间建立起有效的连接。 Apache Linkis 1.3.0及之前版本存在代码问题漏洞,该漏洞源于当攻击者拥有对数据库的写入权限并使用MySQL数据源和恶意参数配置新数据源时,存在可能影响远程代码执行的反序列化漏洞。
CVSS Information
N/A
Vulnerability Type
N/A