CVE-2023-27987
Summary
| CVE | CVE-2023-27987 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-10 08:15:00 UTC |
| Updated | 2023-04-14 19:46:00 UTC |
| Description | In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrade the version of Linkis to version 1.3.2 And modify the default token value. You can refer to Token authorization[1] https://linkis.apache.org/docs/latest/auth/token https://linkis.apache.org/docs/latest/auth/token |
Risk And Classification
Problem Types: CWE-326
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CVE-2023-27987: Apache Linkis gateway module token authentication bypass | MISC | www.openwall.com | Mailing List |
| lists.apache.org/thread/3cr1cz3210wzwngldwrqzm43vwhghp0p | MISC | lists.apache.org | Mailing List, Vendor Advisory |
| oss-security - CVE-2023-27987: Apache Linkis gateway module token authentication bypass | MITRE | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.