GHSA-j6vx-r77h-44wc

Suggest an improvement
Source
https://github.com/advisories/GHSA-j6vx-r77h-44wc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-j6vx-r77h-44wc/GHSA-j6vx-r77h-44wc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j6vx-r77h-44wc
Aliases
Published
2024-08-02T12:31:43Z
Modified
2024-08-16T18:46:41.664145Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Apache Linkis arbitrary file deletion vulnerability
Details

In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on a user with an administrator account could delete any file accessible by the Linkis system user. Users are recommended to upgrade to version 1.6.0, which fixes this issue.

References

Affected packages

Maven / org.apache.linkis:linkis

Package

Name
org.apache.linkis:linkis
View open source insights on deps.dev
Purl
pkg:maven/org.apache.linkis/linkis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.0

Affected versions

1.*

1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.3.0
1.3.1
1.3.2
1.4.0
1.5.0