Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 10 Apr 2023 06:14:37 +0000
From: Heping Wang <>
Subject: CVE-2023-27602: Apache Linkis publicsercice module unrestricted
 upload of file 

Severity: important


In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.

We recommend users upgrade the version of Linkis to version 1.3.2. 

For versions 

<=1.3.1, we suggest turning on the file path check switch in



Laihan (reporter)


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.