Deserialization of Untrusted Data in Linkis - CVE-2023-29216
Published: April 10, 2023
Linkis
Apache Foundation
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote user can leverage the MySQL data source and malicious parameters to
configure a new data source and execute arbitrary code on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.