CVE-2023-27603



In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path,This is a Zip Slip issue, which will lead to apotential RCE vulnerability.


We recommend users upgrade the version of Linkis to version 1.3.2.



Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H