High severity7.5NVD Advisory· Published Sep 25, 2024· Updated Jun 17, 2026
CVE-2024-39928
CVE-2024-39928
Description
In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons Lang's RandomStringUtils. Users are recommended to upgrade to version 1.6.0, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.linkis:linkis-engineplugin-sparkMaven | < 1.6.0 | 1.6.0 |
Affected products
3- Apache Software Foundation/Apache Linkis Spark EngineConnv5Range: 1.3.0
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2024/09/24/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-6gch-63wp-4v5fghsaADVISORY
- lists.apache.org/thread/g664n13nb17rsogcfrn8kjgd8m89p8nwnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-39928ghsaADVISORY
- github.com/apache/linkis/commit/82c2f4b201b746e9206bb58ef98f536fc333aa07ghsaWEB
News mentions
0No linked articles in our index yet.