PT-2025-38621 · Apache · Apache Linkis
Kinghao
+1
·
Published
2025-09-19
·
Updated
2026-01-24
·
CVE-2025-29847
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Linkis versions 1.3.0 through 1.7.0
Description
A flaw exists in Apache Linkis when utilizing the JDBC engine and data source functionality. Multiple rounds of URL encoding applied to the URL parameter configured on the frontend can circumvent system checks. This bypass may enable unauthorized access to system files through JDBC parameters. The issue is related to insufficient validation of connection information, specifically regarding the presence of the '%' character.
Recommendations
Upgrade to version 1.8.0, which addresses this issue.
Continuously check if the connection information contains the "%" character and perform URL decoding if it does.
Fix
Path traversal
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Linkis