CVE-2024-27182: Apache Linkis Basic management services: Engine material management Arbitrary file deletion vulnerability
In Apache Linkis <= 1.5.0,
Arbitrary file deletion in Basic management services on
A user with an administrator account could delete any file accessible by the Linkis system user
. Users are recommended to upgrade to version 1.6.0, which fixes this issue.
Other sources
In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on a user with an administrator account could delete any file accessible by the Linkis system user. Users are recommended to upgrade to version 1.6.0, which fixes this issue.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27182?
CVE-2024-27182 has a high severity due to the potential for arbitrary file deletion by administrators.
How do I fix CVE-2024-27182?
To fix CVE-2024-27182, users should upgrade to Apache Linkis version 1.6.0 or later.
What versions of Apache Linkis are affected by CVE-2024-27182?
CVE-2024-27182 affects Apache Linkis versions up to and including 1.5.0.
Can unauthorized users exploit CVE-2024-27182?
No, only users with administrator accounts can exploit CVE-2024-27182 for arbitrary file deletion.
What action should I take if I can't upgrade from version 1.5.0 to fix CVE-2024-27182?
If unable to upgrade, consider implementing strict access controls to mitigate the risk associated with CVE-2024-27182.