CVE-2023-27602: Apache Linkis publicsercice module unrestricted upload of file

2023-04-10 Thread peacewong
*Severity:* important *Description:* In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2. *Credit:* Laihan (reporter) *References:* https://list

CVE-2023-27602: Apache Linkis publicsercice module unrestricted upload of file

2023-04-09 Thread Heping Wang
Severity: important Description: In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2.  For versions <=1.3.1, we suggest turning on the file