SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2023-27602

CRITICAL · CVSS 9.8 EPSS 2.00%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-04-10 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache.

CVE
CVE-2023-27602
Severity
CRITICAL
CVSS
9.8
EPSS
2.00%
Apache

Original NVD Description

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2.  For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties `wds.linkis.workspace.filesystem.owner.check=true` `wds.linkis.workspace.filesystem.path.check=true`

Related CVEs

Other vulnerabilities affecting the same vendor(s)