-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.linkis:linkis-datasource | maven | < 1.6.0 | 1.6.0 |
The vulnerability stems from unvalidated DB2 JDBC parameters allowing JNDI injection. The primary vulnerable functions would be in the DB2 datasource handling layer where connection parameters are processed. The Db2DataSourceManager class is explicitly mentioned in the vulnerability context, and connection creation methods would be the injection point. The medium-confidence function covers general JDBC URL construction that might handle attacker-controlled input before parameter filtering was added in 1.6.0. The high confidence comes from the direct association between DB2 datasource management and the vulnerability description's specific mention of DB2 parameter handling flaws.
Ongoing coverage of React2Shell