https://seclists.org/oss-sec/2024/q1/189: CVE-2023-50740: Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
Published Mar 6, 2024
·Updated
Affected Software
1 affected component
Apache linkis
Frequently Asked Questions
1
What is the severity of CVE-2023-50740?
CVE-2023-50740 has been classified as a high-severity vulnerability due to the exposure of sensitive database credentials.
2
How do I fix CVE-2023-50740?
To fix CVE-2023-50740, update to the latest version of Apache Linkis where the vulnerability has been addressed and follow best practices for securing database credentials.
3
What are the potential impacts of CVE-2023-50740?
CVE-2023-50740 could allow unauthorized access to the Oracle SQL database by exposing sensitive passwords in logs.
4
Which versions of Apache Linkis are affected by CVE-2023-50740?
CVE-2023-50740 affects Apache Linkis versions prior to the patch release mentioned in the advisory.
5
Is there a workaround for CVE-2023-50740?
While it is best to upgrade, temporarily disabling logging of sensitive information may serve as a workaround until a patch is applied.