Arbitrary file upload in Linkis - CVE-2023-27603
Published: April 10, 2023
Linkis
Apache Foundation
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload when handling .zip archives within the Manager module engineConn. A remote attacker can upload a malicious archive and execute arbitrary files on the server once the archive is unpacked.