Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability allows attackers to bypass the security mechanisms of InLong
JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
Metrics
Affected Vendors & Products
References
History
Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache inlong |
|
| CPEs | cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache inlong |
Wed, 28 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 28 May 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 28 May 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/11747 | |
| Title | Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read | |
| Weaknesses | CWE-502 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published: 2025-05-28T08:12:27.609Z
Updated: 2025-05-28T13:20:49.864Z
Reserved: 2025-02-27T07:32:40.617Z
Link: CVE-2025-27528
Updated: 2025-05-28T09:04:24.174Z
Status : Analyzed
Published: 2025-05-28T08:15:21.830
Modified: 2025-06-03T15:36:47.120
Link: CVE-2025-27528
No data.