PT-2025-38621 · Apache · Apache Linkis

·

CVE-2025-29847

·

Published

2025-09-19

·

Updated

2026-01-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Linkis versions 1.3.0 through 1.7.0
Description A flaw exists in Apache Linkis when utilizing the JDBC engine and data source functionality. Multiple rounds of URL encoding applied to the URL parameter configured on the frontend can circumvent system checks. This bypass may enable unauthorized access to system files through JDBC parameters. The issue is related to insufficient validation of connection information, specifically regarding the presence of the '%' character.
Recommendations Upgrade to version 1.8.0, which addresses this issue. Continuously check if the connection information contains the "%" character and perform URL decoding if it does.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29847
GHSA-C399-Q49H-QWC8

Affected Products

Apache Linkis