CVE-2023-27603: Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue
In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability.
We recommend users upgrade the version of Linkis to version 1.3.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27603?
CVE-2023-27603 is classified as a potential remote code execution (RCE) vulnerability due to a Zip Slip issue.
How do I fix CVE-2023-27603?
To remediate CVE-2023-27603, users should upgrade Apache Linkis to version 1.3.2 or later.
Which versions of Apache Linkis are affected by CVE-2023-27603?
CVE-2023-27603 affects all versions of Apache Linkis up to and including 1.3.1.
What is a Zip Slip issue in the context of CVE-2023-27603?
A Zip Slip issue occurs when an application extracts files from a zip archive without properly validating the file paths, potentially leading to unauthorized file system access.
What type of applications are vulnerable due to CVE-2023-27603?
Applications using Apache Linkis versions 1.3.1 or earlier that handle ZIP file extraction incorrectly are vulnerable to CVE-2023-27603.