Vulnerability Details CVE-2024-27181
In Apache Linkis <= 1.5.0,
Privilege Escalation in Basic management services where the attacking user is
a trusted account
allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.7%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2024-27181
-
cpe:2.3:a:apache:linkis:0.10.0
-
cpe:2.3:a:apache:linkis:0.11.0
-
cpe:2.3:a:apache:linkis:0.5.0
-
cpe:2.3:a:apache:linkis:0.6.0
-
cpe:2.3:a:apache:linkis:0.7.0
-
cpe:2.3:a:apache:linkis:0.8.0
-
cpe:2.3:a:apache:linkis:0.9.0
-
cpe:2.3:a:apache:linkis:0.9.1
-
cpe:2.3:a:apache:linkis:0.9.2
-
cpe:2.3:a:apache:linkis:0.9.3
-
cpe:2.3:a:apache:linkis:0.9.4
-
cpe:2.3:a:apache:linkis:1.0.0
-
cpe:2.3:a:apache:linkis:1.0.1
-
cpe:2.3:a:apache:linkis:1.0.2
-
cpe:2.3:a:apache:linkis:1.0.3
-
cpe:2.3:a:apache:linkis:1.1.0
-
cpe:2.3:a:apache:linkis:1.1.1
-
cpe:2.3:a:apache:linkis:1.1.2
-
cpe:2.3:a:apache:linkis:1.1.3
-
cpe:2.3:a:apache:linkis:1.2.0
-
cpe:2.3:a:apache:linkis:1.3.0
-
cpe:2.3:a:apache:linkis:1.3.2
-
cpe:2.3:a:apache:linkis:1.4.0
-
cpe:2.3:a:apache:linkis:1.5.0