Linkis
Vendor:
First CVE: Oct 26, 2022 · Active for 3 years
18
Total CVEs
More Total CVEs than 93% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Linkis over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2022
3 years ago
Most Recent CVE
Jan 19, 2026
187 days ago
CVE Severity & Scoring
Linkis18 CVEs
33%
39%
28%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.6%)
Network17 (94.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (44.4%)
High1 (5.6%)
None9 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29216CRITICAL In Apache Linkis <=1.3.1, because the parameters are not
effectively filtered, the attacker uses the MySQL data source and malicious parameters to
configure a new data source to tr | Apr 10, 2023 | 9.8 | 32 | NO | NO |
CVE-2023-29215CRITICAL In Apache Linkis <=1.3.1, due to the lack of effective filtering
of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a
de | Apr 10, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-27603CRITICAL
In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerab | Apr 10, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-27602CRITICAL In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
We recommend users upgrade the version of | Apr 10, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-39944HIGH In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access t | Oct 26, 2022 | 8.8 | 29 | NO | NO |
CVE-2023-27987CRITICAL
In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Ge | Apr 10, 2023 | 9.1 | 28 | NO | NO |
CVE-2023-46801HIGH
In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version < 1.8.0_241. The deserializati | Jul 15, 2024 | 8.8 | 27 | NO | NO |
CVE-2023-49566HIGH
In Apache Linkis <=1.5.0, due to the lack of effective filtering
of parameters, an attacker configuring malicious
db2
parameters in the DataSource Manager Module will result i | Jul 15, 2024 | 8.8 | 26 | NO | NO |
CVE-2025-29847HIGH A vulnerability in Apache Linkis.
Problem Description
When using the JDBC engine and da
When using the JDBC engine and data source functionality, if the URL parameter configured o | Jan 19, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-27181HIGH In Apache Linkis <= 1.5.0,
Privilege Escalation in Basic management services where the attacking user is
a trusted account
allows access to Linkis's Token information. Users a | Aug 2, 2024 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Linkis
Top CWEs
Versions
No cataloged versions.