https://seclists.org/oss-sec/2024/q3/65: CVE-2023-46801: Apache Linkis DataSource: mote code execution vulnerability in apache Linkis 1.4.0
Published Jul 13, 2024
·Updated
Affected Software
1 affected component
Apache linkis<1.6.0
Frequently Asked Questions
1
What is the severity of CVE-2023-46801?
CVE-2023-46801 has a moderate severity rating.
2
What versions of Apache Linkis are affected by CVE-2023-46801?
Apache Linkis DataSource versions 1.4.0 through 1.5.0 are affected by CVE-2023-46801.
3
How do I fix CVE-2023-46801?
To fix CVE-2023-46801, upgrade Apache Linkis to version 1.6.0 or later.
4
What type of vulnerability is CVE-2023-46801?
CVE-2023-46801 is a remote code execution vulnerability caused by deserialization issues in the data source management module.
5
Which Java versions are at risk for CVE-2023-46801?
CVE-2023-46801 affects systems running Java versions prior to 1.8.0_241.