CVE-2023-49566 is a high-severity JNDI injection vulnerability in Apache Linkis versions <=1.5.0, where an authenticated attacker can configure malicious db2 parameters in the DataSource Manager Module. This allows for remote code execution with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 8.8. While the vulnerability requires prior authentication, there is currently no public exploit code, Metasploit modules, or significant community discussion, suggesting it is not actively exploited in the wild. Users are advised to upgrade to Linkis version 1.6.0 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.0, < 1.6.0CPE matchmatch criteria | cpe:2.3:a:apache:linkis:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.