CVE-2024-27181: Apache Linkis Basic management services: Privilege Escalation Attack vulnerability
Published Aug 2, 2024
·Updated
In Apache Linkis <= 1.5.0,
Privilege Escalation in Basic management services where the attacking user is
a trusted account
allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue.
Affected Software
2 affected componentsFixes available
Apache linkis<1.6.0
maven/org.apache.linkis:linkis<1.6.0
1.6.0
Event History
Aug 2, 2024
CVE Published
via MITRE·09:27 AM
Data Sourced
via MITRE·09:27 AM
DescriptionWeakness
Advisory Published
via GitHub·12:31 PM
Data Sourced
via GitHub·12:31 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27181?
CVE-2024-27181 has been classified as a privilege escalation vulnerability.
2
How do I fix CVE-2024-27181?
To fix CVE-2024-27181, users should upgrade to Apache Linkis version 1.6.0 or later.
3
What versions of Apache Linkis are affected by CVE-2024-27181?
Apache Linkis versions up to and including 1.5.0 are affected by CVE-2024-27181.
4
What type of vulnerability is CVE-2024-27181?
CVE-2024-27181 is a privilege escalation vulnerability that can be exploited by trusted accounts.
5
Who should be concerned about CVE-2024-27181?
Administrators and users of Apache Linkis versions 1.5.0 and earlier should be concerned about CVE-2024-27181.