https://seclists.org/oss-sec/2024/q3/64: CVE-2023-49566: Apache Linkis DataSource: JDBC Datasource Module with DB2 has JNDI Injection vulnerability
Published Jul 13, 2024
·Updated
Affected Software
1 affected component
Apache linkis<1.6.0
The severity of CVE-2023-49566 is classified as important.
To fix CVE-2023-49566, upgrade Apache Linkis to version 1.6.0 or later.
Apache Linkis versions before 1.6.0 are affected by CVE-2023-49566.
CVE-2023-49566 is a JNDI Injection vulnerability in the JDBC Datasource Module with DB2.
Attackers can exploit CVE-2023-49566 by configuring malicious DB2 parameters in the DataSource Manager Module to execute JNDI Injection.