Apache Linkis£¨Incubating£©ÊÇÒ»¸ö¿ªÔ´µÄÉϲãÓ¦ÓÃÓëµ×²ãÒýÇæÖ®¼äµÄ¼ÆËãÖмä¼þ£¬ÌṩÁËÇ¿´óµÄÁ¬½Ó¡¢¸´ÓᢱàÅÅ¡¢À©Õ¹ºÍ´¦ÀíÄÜÁ¦¡£»Æ½ð³Ç»Æ½ð³Ç¹ÙÍøÊµÑéÊÒ¼à²âµ½Apache¹Ù·½·¢²¼»Æ½ð³Ç¹ÙÍø¹«¸æ£¬ÐÞ¸´ÁËLinkis DatasourceManagerÄ£¿éÖеÄÒ»¸ö·´ÐòÁл¯Â©¶´ºÍÒ»¸öÎļþ¶Áȡ©¶´£¬Â©¶´±àºÅ£ºCVE-2022-44645£¬CVE-2022-44644£¬Â©¶´µÈ¼¶£º¸ßΣ¡£- CVE-2022-44645: Apache Linkis·´ÐòÁл¯Â©¶´
¼òÊö£ºApache Linkis°æ±¾<=1.3.0ÓëMySQL Connector/JÒ»ÆðʹÓÃʱ£¬µ±¶ÔÊý¾Ý¿â¾ßÓÐдÈëȨÏÞ²¢Ê¹ÓÃMySQLÊý¾ÝÔ´ºÍ¶ñÒâ²ÎÊýÅäÖÃÐÂÊý¾ÝԴʱ£¬´æÔÚ·´ÐòÁл¯Â©¶´£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£- CVE-2022-44644: Apache LinkisÎļþ¶Áȡ©¶´
¼òÊö£ºApache Linkis°æ±¾<=1.3.0ÓëMySQL Connector/JÒ»ÆðʹÓÃʱ£¬Í¨¹ýÔÚjdbc²ÎÊýÖн«allowLoadLocalInfileÌí¼ÓΪtrue£¬¾¹ýÉí·ÝÑéÖ¤µÄÓû§¿ÉÒÔͨ¹ýÁ¬½Ó¶ñÒâMySQL·þÎñÆ÷¶ÁÈ¡ÈÎÒâ±¾µØÎļþ¡£Ä¿Ç°ÊÜÓ°ÏìµÄApache Linkis°æ±¾£º
ĿǰÕâЩ©¶´ÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿É¼°Ê±Éý¼¶µ½Apache Linkis 1.3.1°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://github.com/apache/linkis/releases