PT-2022-5283 · Apache+1 · Apache Linkis+1

4Ra1N

+2

·

Published

2022-10-26

·

Updated

2022-10-28

·

CVE-2022-39944

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Linkis versions 1.2.0 and earlier
Description A deserialization vulnerability exists in Apache Linkis when used with the MySQL Connector/J, potentially allowing remote code execution if an attacker has write access to a database and configures a JDBC EC with a MySQL data source and malicious parameters. The issue is related to the restoration of untrusted data in memory.
Recommendations For Apache Linkis versions 1.2.0 and earlier, update to version 1.3.0 to resolve the issue. As a temporary workaround, consider blacklisting parameters in the jdbc url to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2022-06567
CVE-2022-39944
GHSA-3F3W-GMQF-4HJ3

Affected Products

Apache Linkis
Mysql Connector/J