In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by the Linkis system user . Users are recommended to upgrade to version 1.6.0, which fixes this issue.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://lists.apache.org/thread/2of1p433h8rbq2bx525rtftnk19oz38h | vendor advisory mailing list |
http://www.openwall.com/lists/oss-security/2024/08/02/4 |