Linkis
Apache · 18 CVEs
Apache Linkis: Password Exposure
Jan 19, 2026
Apache Linkis: Arbitrary File Read via Double URL Encoding Bypass
Jan 19, 2026
Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability
Jan 14, 2025
Apache Linkis Spark EngineConn: Commons Lang's RandomStringUtils Random string security vulnerability
Sep 24, 2024
Apache Linkis Basic management services: Engine material management Arbitrary file deletion vulnerability
Aug 2, 2024
Apache Linkis Basic management services: Privilege Escalation Attack vulnerability
Aug 2, 2024
Apache Linkis DataSource: JDBC Datasource Module with DB2 has JNDI Injection vulnerability
Jul 15, 2024
Apache Linkis DataSource: DataSource Remote code execution vulnerability
Jul 15, 2024
Apache Linkis DataSource: DatasourceManager module has a JDBC parameter judgment logic vulnerability that allows for a…
Jul 15, 2024
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Mar 6, 2024
Apache Linkis DatasourceManager module has a deserialization command execution
Apr 10, 2023
Apache Linkis gateway module token authentication bypass
Apr 10, 2023
Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue
Apr 10, 2023
Apache Linkis publicsercice module unrestricted upload of file
Apr 10, 2023
Apache Linkis JDBC EngineCon has a deserialization command execution
Apr 10, 2023
Apache Linkis (incubating): The DatasourceManager module has a Local File Read Vulnerability
Jan 31, 2023
Apache Linkis (incubating): The DatasourceManager module has a serialization attack vulnerability
Jan 31, 2023
The Apache Linkis JDBC EngineConn module has a RCE Vulnerability
Oct 26, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-59355 | Apache Linkis: Password Exposure | MEDIUM | 0.46% | Jan 19, 2026 |
| CVE-2025-29847 | Apache Linkis: Arbitrary File Read via Double URL Encoding Bypass | HIGH | 0.85% | Jan 19, 2026 |
| CVE-2024-45627 | Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability | MEDIUM | 0.32% | Jan 14, 2025 |
| CVE-2024-39928 | Apache Linkis Spark EngineConn: Commons Lang's RandomStringUtils Random string security vulnerability | HIGH | 0.58% | Sep 24, 2024 |
| CVE-2024-27182 | Apache Linkis Basic management services: Engine material management Arbitrary file deletion vulnerability | HIGH | 0.74% | Aug 2, 2024 |
| CVE-2024-27181 | Apache Linkis Basic management services: Privilege Escalation Attack vulnerability | HIGH | 0.64% | Aug 2, 2024 |
| CVE-2023-49566 | Apache Linkis DataSource: JDBC Datasource Module with DB2 has JNDI Injection vulnerability | HIGH | 0.84% | Jul 15, 2024 |
| CVE-2023-46801 | Apache Linkis DataSource: DataSource Remote code execution vulnerability | HIGH | 1.23% | Jul 15, 2024 |
| CVE-2023-41916 | Apache Linkis DataSource: DatasourceManager module has a JDBC parameter judgment logic vulnerability that allows for arbitrary file reading | HIGH | 0.73% | Jul 15, 2024 |
| CVE-2023-50740 | Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged | MEDIUM | 0.90% | Mar 6, 2024 |
| CVE-2023-29216 | Apache Linkis DatasourceManager module has a deserialization command execution | CRITICAL | 2.12% | Apr 10, 2023 |
| CVE-2023-27987 | Apache Linkis gateway module token authentication bypass | CRITICAL | 0.81% | Apr 10, 2023 |
| CVE-2023-27603 | Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue | CRITICAL | 1.81% | Apr 10, 2023 |
| CVE-2023-27602 | Apache Linkis publicsercice module unrestricted upload of file | CRITICAL | 2.00% | Apr 10, 2023 |
| CVE-2023-29215 | Apache Linkis JDBC EngineCon has a deserialization command execution | CRITICAL | 2.12% | Apr 10, 2023 |
| CVE-2022-44644 | Apache Linkis (incubating): The DatasourceManager module has a Local File Read Vulnerability | MEDIUM | 1.16% | Jan 31, 2023 |
| CVE-2022-44645 | Apache Linkis (incubating): The DatasourceManager module has a serialization attack vulnerability | HIGH | 1.93% | Jan 31, 2023 |
| CVE-2022-39944 | The Apache Linkis JDBC EngineConn module has a RCE Vulnerability | HIGH | 1.93% | Oct 26, 2022 |
Showing 1 to 18 of 18 CVEs