https://seclists.org/oss-sec/2024/q1/189: CVE-2023-50740: Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Published Mar 6, 2024
·Updated
Affected Software
1 affected component
Apache linkis
CVE-2023-50740 has been classified as a high-severity vulnerability due to the exposure of sensitive database credentials.
To fix CVE-2023-50740, update to the latest version of Apache Linkis where the vulnerability has been addressed and follow best practices for securing database credentials.
CVE-2023-50740 could allow unauthorized access to the Oracle SQL database by exposing sensitive passwords in logs.
CVE-2023-50740 affects Apache Linkis versions prior to the patch release mentioned in the advisory.
While it is best to upgrade, temporarily disabling logging of sensitive information may serve as a workaround until a patch is applied.