Apache · Apache Linkis · CVE-2024-39928
**Name of the Vulnerable Software and Affected Versions**
Apache Linkis versions 1.3.0 through 1.5.0
**Description**
A Random string security vulnerability exists in Spark EngineConn, where the random string generated by the Token when starting Py4j uses Commons Lang's RandomStringUtils.
**Recommendations**
For Apache Linkis versions 1.3.0 through 1.5.0, upgrade to version 1.6.0 to fix this issue.