PT-2023-8820 · Apache · Apache Linkis

·

CVE-2023-50740

·

Published

2023-12-13

·

Updated

2024-11-08

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Linkis versions <=1.4.0
Description The issue is related to insufficient protection of registration data in Apache Linkis, which may allow a remote attacker to gain unauthorized access to protected information. Specifically, when using the Oracle data source of the Linkis data source module, the password is printed to the log.
Recommendations For Apache Linkis versions <=1.4.0, upgrade the version of Linkis to version 1.5.0 to resolve the issue.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02069
CVE-2023-50740
GHSA-M757-P8RV-4Q93

Affected Products

Apache Linkis