CVE-2023-27603

CVE-2023-27603: Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue

Vendor Apache Software Foundation
Product Apache Linkis
Weakness CWE-22 · Path traversal
Published April 10, 2023
Last update October 22, 2024

CVSS base score

What the vulnerability does

Description

In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.

Key dates

Disclosure timeline

April 10, 2023 CVE published
October 22, 2024 Record updated