https://seclists.org/oss-sec/2025/q3/173: CVE-2025-59355: Apache Linkis: Password Exposu
Published Sep 19, 2025
·Updated
Affected Software
1 affected component
Apache linkis>=1.0.0<=1.7.0
The severity of CVE-2025-59355 is classified as low.
Apache Linkis versions 1.0.0 through 1.7.0 are affected by CVE-2025-59355.
CVE-2025-59355 allows for the complete input parameter string to be logged if Base64 decoding fails.
To fix CVE-2025-59355, upgrade to a version of Apache Linkis that is above 1.7.0.
CVE-2025-59355 is a password exposure vulnerability due to improper logging of input parameters.