CVE-2024-39928

Source
https://cve.org/CVERecord?id=CVE-2024-39928
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39928.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39928
Aliases
Published
2024-09-24T07:27:55Z
Modified
2026-08-12T15:15:22Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Apache Linkis Spark EngineConn: Commons Lang's RandomStringUtils Random string security vulnerability
Details

In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons Lang's RandomStringUtils. Users are recommended to upgrade to version 1.6.0, which fixes this issue.

Database specific
{
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-326"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39928.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.3.0"
                },
                {
                    "fixed": "1.6.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/apache/linkis

Affected ranges

Type
GIT
Repo
https://github.com/apache/linkis
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:apache:linkis:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.3.0"
        },
        {
            "fixed": "1.6.0"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39928.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "60828749064976347165812819771182215424",
            "length": 1879
        },
        "id": "CVE-2024-39928-0ea3ea5d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/apache/linkis/commit/9be69de555a4539c73b56dd44c798026596f0f54",
        "target": {
            "file": "linkis-computation-governance/linkis-entrance/src/main/java/org/apache/linkis/entrance/restful/EntranceRestfulApi.java",
            "function": "submit"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "225731198629722605236678847431119311777",
                "206877223739141534512710189071403489297",
                "265000549159365350083479690704441430136",
                "334199407620554550494929358819571833638",
                "225731198629722605236678847431119311777",
                "206877223739141534512710189071403489297",
                "184922721631577521172341610262425618245",
                "107429859391792390745803307503868481895"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2024-39928-59b2da89",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/apache/linkis/commit/9be69de555a4539c73b56dd44c798026596f0f54",
        "target": {
            "file": "linkis-computation-governance/linkis-entrance/src/main/java/org/apache/linkis/entrance/restful/EntranceRestfulApi.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "192796447668438242518408730468241430717",
            "length": 1548
        },
        "id": "CVE-2024-39928-be993fad",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/apache/linkis/commit/9be69de555a4539c73b56dd44c798026596f0f54",
        "target": {
            "file": "linkis-computation-governance/linkis-entrance/src/main/java/org/apache/linkis/entrance/restful/EntranceRestfulApi.java",
            "function": "execute"
        }
    }
]
vanir_signatures_modified
"2026-08-12T15:15:22Z"