PT-2023-21244 · Apache · Apache Linkis

4Ra1N

·

Published

2023-04-10

·

Updated

2024-10-22

·

CVE-2023-27603

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Linkis versions 1.3.1 and earlier
Description The issue is related to a Zip Slip problem in the Manager module engineConn material upload, which does not check the zip path. This can lead to a potential RCE vulnerability.
Recommendations For Apache Linkis versions 1.3.1 and earlier, upgrade the version of Linkis to version 1.3.2.

Fix

Path traversal

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-27603
GHSA-PJ5J-W7MW-W797

Affected Products

Apache Linkis