PT-2024-28740 · Apache · Commons Lang+2

+1

·

CVE-2024-39928

·

Published

2024-09-24

·

Updated

2024-09-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Linkis versions 1.3.0 through 1.5.0
Description A Random string security vulnerability exists in Spark EngineConn, where the random string generated by the Token when starting Py4j uses Commons Lang's RandomStringUtils.
Recommendations For Apache Linkis versions 1.3.0 through 1.5.0, upgrade to version 1.6.0 to fix this issue.

Exploit

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39928
GHSA-6GCH-63WP-4V5F

Affected Products

Apache Linkis
Commons Lang
Spark Engineconn