PT-2023-8820 · Apache · Apache Linkis

Jonathan Leitschuh

·

Published

2023-12-13

·

Updated

2024-11-08

·

CVE-2023-50740

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Linkis versions <=1.4.0
Description The issue is related to insufficient protection of registration data in Apache Linkis, which may allow a remote attacker to gain unauthorized access to protected information. Specifically, when using the Oracle data source of the Linkis data source module, the password is printed to the log.
Recommendations For Apache Linkis versions <=1.4.0, upgrade the version of Linkis to version 1.5.0 to resolve the issue.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2024-02069
CVE-2023-50740
GHSA-M757-P8RV-4Q93

Affected Products

Apache Linkis