PT-2024-28740 · Apache · Apache Linkis+2

Hen

+1

·

Published

2024-09-24

·

Updated

2024-09-30

·

CVE-2024-39928

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Linkis versions 1.3.0 through 1.5.0
Description A Random string security vulnerability exists in Spark EngineConn, where the random string generated by the Token when starting Py4j uses Commons Lang's RandomStringUtils.
Recommendations For Apache Linkis versions 1.3.0 through 1.5.0, upgrade to version 1.6.0 to fix this issue.

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2024-39928
GHSA-6GCH-63WP-4V5F

Affected Products

Apache Linkis
Commons Lang
Spark Engineconn