https://seclists.org/oss-sec/2025/q3/174: CVE-2025-29847: Apache Linkis: Arbitrary File ad via Double URL Encoding Bypass
Published Sep 19, 2025
·Updated
Affected Software
1 affected component
Apache linkis>=1.3.0<=1.7.0
Frequently Asked Questions
1
What is the severity of CVE-2025-29847?
CVE-2025-29847 has a moderate severity level.
2
What versions of Apache Linkis are affected by CVE-2025-29847?
CVE-2025-29847 affects Apache Linkis versions 1.3.0 through 1.7.0.
3
How does CVE-2025-29847 exploit the vulnerability?
CVE-2025-29847 exploits an arbitrary file access issue via double URL encoding bypass when using the JDBC engine.
4
How do I fix CVE-2025-29847?
To mitigate CVE-2025-29847, upgrade Apache Linkis to a version later than 1.7.0.
5
What functionalities in Apache Linkis are impacted by CVE-2025-29847?
CVE-2025-29847 impacts the JDBC engine and data source functionalities when using flawed URL parameters.