org.apache.linkis:linkis-common@1.8.0 vulnerabilities

  • latest version

    1.8.0

  • first published

    4 years ago

  • latest version published

    3 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.linkis:linkis-common package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Encoding Error

    org.apache.linkis:linkis-common is a module that builds a computation middleware layer to facilitate connection, governance and orchestration between the upper applications and the underlying data engines.

    Affected versions of this package are vulnerable to Encoding Error via the handling of JDBC parameters when multiple rounds of URL encoding are applied. An attacker can access arbitrary system files by submitting specially crafted requests that bypass input validation through double URL encoding.

    How to fix Encoding Error?

    A fix was pushed into the master branch but not yet published.

    [0,)