Critical severity9.1NVD Advisory· Published Apr 10, 2023· Updated Jun 17, 2026
CVE-2023-27987
CVE-2023-27987
Description
In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values.
We recommend users upgrade the version of Linkis to version 1.3.2 And modify the default token value. You can refer to Token authorization[1] https://linkis.apache.org/docs/latest/auth/token https://linkis.apache.org/docs/latest/auth/token
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.linkis:linkisMaven | < 1.3.2 | 1.3.2 |
Affected products
3- Apache Software Foundation/Apache Linkisv5Range: 0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-4x5h-xmv4-99wxghsaADVISORY
- lists.apache.org/thread/3cr1cz3210wzwngldwrqzm43vwhghp0pnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-27987ghsaADVISORY
- linkis.apache.org/docs/latest/auth/tokenghsaWEB
- www.openwall.com/lists/oss-security/2023/04/10/3nvdMailing ListWEB
News mentions
0No linked articles in our index yet.