In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module.
We recommend users upgrade the version of Linkis to version 1.5.0
References
| Link | Resource |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/03/06/2 | Mailing List |
| https://lists.apache.org/thread/5o342chnpyd6rps68ygzfkzycxl998yo | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2024/03/06/2 | Mailing List |
| https://lists.apache.org/thread/5o342chnpyd6rps68ygzfkzycxl998yo | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-03-06 14:15
Updated : 2025-05-07 15:46
NVD link : CVE-2023-50740
Mitre link : CVE-2023-50740
CVE.ORG link : CVE-2023-50740
JSON object : View
Products Affected
apache
- linkis
CWE
CWE-532
Insertion of Sensitive Information into Log File
