https://seclists.org/oss-sec/2024/q3/64: CVE-2023-49566: Apache Linkis DataSource: JDBC Datasource Module with DB2 has JNDI Injection vulnerability
Published Jul 13, 2024
·Updated
Affected Software
1 affected component
Apache linkis<1.6.0
Frequently Asked Questions
1
What is the severity of CVE-2023-49566?
The severity of CVE-2023-49566 is classified as important.
2
How do I fix CVE-2023-49566?
To fix CVE-2023-49566, upgrade Apache Linkis to version 1.6.0 or later.
3
Which versions of Apache Linkis are affected by CVE-2023-49566?
Apache Linkis versions before 1.6.0 are affected by CVE-2023-49566.
4
What type of vulnerability is CVE-2023-49566?
CVE-2023-49566 is a JNDI Injection vulnerability in the JDBC Datasource Module with DB2.
5
What can attackers exploit in CVE-2023-49566?
Attackers can exploit CVE-2023-49566 by configuring malicious DB2 parameters in the DataSource Manager Module to execute JNDI Injection.