PT-2023-8820 · Apache · Apache Linkis
Jonathan Leitschuh
·
Published
2023-12-13
·
Updated
2024-11-08
·
CVE-2023-50740
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Linkis versions <=1.4.0
Description
The issue is related to insufficient protection of registration data in Apache Linkis, which may allow a remote attacker to gain unauthorized access to protected information. Specifically, when using the Oracle data source of the Linkis data source module, the password is printed to the log.
Recommendations
For Apache Linkis versions <=1.4.0, upgrade the version of Linkis to version 1.5.0 to resolve the issue.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Linkis