CVE-2022-39944

CVE-2022-39944: The Apache Linkis JDBC EngineConn module has a RCE Vulnerability

Vendor Apache Software Foundation
Product Apache Linkis
Published October 26, 2022
Last update May 7, 2025

CVSS base score

What the vulnerability does

Description

In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and malicious parameters. Therefore, the parameters in the jdbc url should be blacklisted. Versions of Apache Linkis <= 1.2.0 will be affected, We recommend users to update to 1.3.0.

Key dates

Disclosure timeline

October 26, 2022 CVE published
May 7, 2025 Record updated