CVE-2022-44644, GHSA-rx76-xw35-6rh8
maven/org.apache.linkis/linkis
Exposure of Sensitive Information to an Unauthorized Actor
In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, an authenticated attacker could read arbitrary local file by connecting a rogue mysql server, By adding allowLoadLocalInfile to true in the jdbc parameter. Therefore, the parameters in the jdbc url should be block listed. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users upgrade the version of Linkis to version 1.3
All versions up to 1.3.0
Unfortunately, there is no solution available yet.
2023-02-02
source |