org.apache.linkis:linkis-engineplugin-spark@1.3.1 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.linkis:linkis-engineplugin-spark package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Inadequate Encryption Strength

Affected versions of this package are vulnerable to Inadequate Encryption Strength via the RandomStringUtils function due to the use of insecure random string generation in the token initialization process. An attacker can predict or reproduce the token used in authentication by exploiting the weak randomness of the token generation method.

How to fix Inadequate Encryption Strength?

Upgrade org.apache.linkis:linkis-engineplugin-spark to version 1.6.0 or higher.

[1.3.0,1.6.0)