Filtered by vendor Apache Software Foundation Subscriptions
Filtered by product Apache Linkis Spark Engineconn Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-39928 1 Apache Software Foundation 1 Apache Linkis Spark Engineconn 2024-11-21 7.5 High
In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons Lang's RandomStringUtils. Users are recommended to upgrade to version 1.6.0, which fixes this issue.