CVE-2022-44644

CVE-2022-44644: Apache Linkis (incubating): The DatasourceManager module has a Local File Read Vulnerability

Vendor Apache Software Foundation
Product Apache Linkis (incubating)
Weakness CWE-20 · Input validation
Published January 31, 2023
Last update March 27, 2025

CVSS base score

What the vulnerability does

01Description

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Therefore, the parameters in the JDBC URL should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected.  We recommend users upgrade the version of Linkis to version 1.3.1

Key dates

02Disclosure timeline

January 31, 2023 CVE published
March 27, 2025 Record updated

Related vulnerabilities

04Related CVE