« Back to list

CVE-2024-27181

Status: AnalyzedHigh (8.8)—

In Apache Linkis <= 1.5.0,

Privilege Escalation in Basic management services where the attacking user is

a trusted account

allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-27181",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-27181",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-02T13:50:17.045234Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache Linkis Basic management services",
          "versions": [
            {
              "status": "affected",
              "version": "1.3.2",
              "lessThan": "1.6.0",
              "versionType": "maven"
            }
          ],
          "packageName": "org.apache.linkis:linkis-pes-publicservice",
          "collectionURL": "https://repo.maven.apache.org/maven2",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:apache:linkis:*:*:*:*:*:*:*:*"
          ],
          "vendor": "apache",
          "product": "linkis",
          "versions": [
            {
              "status": "affected",
              "version": "1.3.2",
              "lessThan": "1.6.0",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-08-02T10:15:59.990",
  "references": [
    {
      "url": "https://lists.apache.org/thread/hosd73l7hxb3rpt5rb0yg0ld11zph4c6",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/08/02/3",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Apache Linkis <= 1.5.0,\n\nPrivilege Escalation in Basic management services where the attacking user is \n\na trusted account\n\n allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue."
    },
    {
      "lang": "es",
      "value": "En Apache Linkis &lt;= 1.5.0, la escalada de privilegios en los servicios de administración básicos donde el usuario atacante es una cuenta de confianza permite el acceso a la información del token de Linkis. Se recomienda a los usuarios actualizar a la versión 1.6.0, que soluciona este problema."
    }
  ],
  "lastModified": "2026-06-17T07:19:22.860",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:linkis:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FE36BC9-326E-4EE2-82E0-E8EC4B3694EF",
              "versionEndExcluding": "1.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}