https://seclists.org/oss-sec/2025/q3/173: CVE-2025-59355: Apache Linkis: Password Exposu
Published Sep 19, 2025
·Updated
Affected Software
1 affected component
Apache linkis>=1.0.0<=1.7.0
Frequently Asked Questions
1
What is the severity of CVE-2025-59355?
The severity of CVE-2025-59355 is classified as low.
2
Which versions of Apache Linkis are affected by CVE-2025-59355?
Apache Linkis versions 1.0.0 through 1.7.0 are affected by CVE-2025-59355.
3
What is the primary issue in CVE-2025-59355?
CVE-2025-59355 allows for the complete input parameter string to be logged if Base64 decoding fails.
4
How can I fix CVE-2025-59355?
To fix CVE-2025-59355, upgrade to a version of Apache Linkis that is above 1.7.0.
5
What type of vulnerability is CVE-2025-59355?
CVE-2025-59355 is a password exposure vulnerability due to improper logging of input parameters.