|
Message-ID: <b563279c-e81e-ed68-7ac6-0afcfb225709@apache.org> Date: Fri, 02 Aug 2024 03:50:11 +0000 From: Heping Wang <peacewong@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2024-27182: Apache Linkis Basic management services: Engine material management Arbitrary file deletion vulnerability Severity: important Affected versions: - Apache Linkis Basic management services 1.3.2 before 1.6.0 Description: In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by the Linkis system user . Users are recommended to upgrade to version 1.6.0, which fixes this issue. Credit: superx (reporter) References: https://linkis.apache.org https://www.cve.org/CVERecord?id=CVE-2024-27182
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.