CVE-2024-39928

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 25, 2024
Updated: Nov 21, 2024
CWE ID 326

Summary

CVE-2024-39928 is a vulnerability affecting Apache Linkis versions prior to 1.6.0. The issue involves a Random string security vulnerability in the Spark EngineConn component, where the random string generated by the Token during startup utilizes the Commons Lang's RandomStringUtils. This weakness could potentially be exploited, putting users at risk. To mitigate this issue, it is strongly recommended to upgrade to the latest version, Apache Linkis 1.6.0, which includes the necessary fixes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share