{"id":"GHSA-x84r-jrqm-3hj8","summary":"Apache Linkis Unrestricted File Upload vulnerability","details":"In Apache Linkis \u003c=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.\n\nWe recommend users upgrade the version of Linkis to version 1.3.2. \n\nFor versions \u003c=1.3.1, we suggest turning on the file path check switch in linkis.properties\n\n`wds.linkis.workspace.filesystem.owner.check=true`\n`wds.linkis.workspace.filesystem.path.check=true`","aliases":["CVE-2023-27602"],"modified":"2025-02-13T19:13:15.628578Z","published":"2023-07-06T19:24:13Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-07-06T21:58:51Z","nvd_published_at":"2023-04-10T08:15:00Z","cwe_ids":["CWE-434"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27602"},{"type":"PACKAGE","url":"https://github.com/apache/linkis"},{"type":"WEB","url":"https://lists.apache.org/thread/wt70jfc0yfs6s5g0wg5dr5klnc48nsp1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/04/10/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/04/18/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/04/19/3"}],"affected":[{"package":{"name":"org.apache.linkis:linkis","ecosystem":"Maven","purl":"pkg:maven/org.apache.linkis/linkis"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.2"}]}],"versions":["1.0.3","1.1.0","1.1.1","1.1.2","1.1.3","1.2.0","1.3.0","1.3.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-x84r-jrqm-3hj8/GHSA-x84r-jrqm-3hj8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}