https://seclists.org/oss-sec/2025/q3/174: CVE-2025-29847: Apache Linkis: Arbitrary File ad via Double URL Encoding Bypass
Published Sep 19, 2025
·Updated
Affected Software
1 affected component
Apache linkis>=1.3.0<=1.7.0
CVE-2025-29847 has a moderate severity level.
CVE-2025-29847 affects Apache Linkis versions 1.3.0 through 1.7.0.
CVE-2025-29847 exploits an arbitrary file access issue via double URL encoding bypass when using the JDBC engine.
To mitigate CVE-2025-29847, upgrade Apache Linkis to a version later than 1.7.0.
CVE-2025-29847 impacts the JDBC engine and data source functionalities when using flawed URL parameters.