CVE-2022-44645

CVE-2022-44645: Apache Linkis (incubating): The DatasourceManager module has a serialization attack vulnerability

Vendor Apache Software Foundation
Product Apache Linkis (incubating)
Weakness CWE-502 · Unsafe deserialization
Published January 31, 2023
Last update March 27, 2025

CVSS base score

What the vulnerability does

01Description

In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and malicious parameters. Therefore, the parameters in the jdbc url should be blacklisted. Versions of Apache Linkis <= 1.3.0 will be affected. We recommend users to upgrade the version of Linkis to version 1.3.1.

Key dates

02Disclosure timeline

January 31, 2023 CVE published
March 27, 2025 Record updated

Related vulnerabilities

04Related CVE