CVE-2023-27603

CVE-2023-27603: Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue

Vendor Apache Software Foundation
Product Apache Linkis
Weakness CWE-22 · Path traversal
Published April 10, 2023
Last update October 22, 2024

CVSS base score

What the vulnerability does

01Description

In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.

Key dates

02Disclosure timeline

April 10, 2023 CVE published
October 22, 2024 Record updated

Related vulnerabilities

04Related CVE