Apache Linkis Metadata Query Service JDBC File Read Vulnerability in DataSource Manager Module

Vulnerability

A file read vulnerability has been identified in the Apache Linkis Metadata Query Service JDBC, specifically in versions prior to 1.7.0. This issue arises from inadequate parameter filtering, which allows an attacker with an authorized Linkis account to inject malicious MySQL JDBC parameters in the DataSource Manager Module. Exploiting this vulnerability could enable the attacker to read arbitrary files from the Linkis server. It is recommended that users upgrade to Apache Linkis version 1.7.0.

Impact

Exploitation of this vulnerability could lead to unauthorized reading of files from the Linkis server.

Remediation

Users are advised to upgrade Apache Linkis to version 1.7.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.