{"schema_version": "1.6.1", "id": "CVE-2023-27603", "summary": "Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue", "details": "\n\n\nIn Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability.\n\n\nWe recommend users upgrade the version of Linkis to version 1.3.2.\n\n\n\n", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "0"}, {"last_affected": "0"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/6n1vlvnyn441rm02zdqc0wnpckj8ltn8"}, {"type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2023/04/10/2"}]}