CVE-2023-27602: Apache Linkis

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2.  For versions <=1.3.1, we suggest turning on the file path check switch in linkis.properties `wds.linkis.workspace.filesystem.owner.check=true` `wds.linkis.workspace.filesystem.path.check=true`

Affected products

  • Apache Linkis: up to and including 1.3.1

Published 2023-04-10. Last modified 2026-06-17.