CVE-2022-44645

Deserialization of Untrusted Data in maven/org.apache.linkis/linkis

Identifiers

CVE-2022-44645, GHSA-h6w8-52mq-4qxc

Package Slug

maven/org.apache.linkis/linkis

Vulnerability

Deserialization of Untrusted Data

Description

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and malicious parameters. Therefore, the parameters in the jdbc url should be block listed. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users to upgrade the version of Linkis to version 1.3.1.

Affected Versions

All versions up to 1.3.0

Solution

Unfortunately, there is no solution available yet.

Last Modified

2023-02-02

source