Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability allows attackers to bypass the security mechanisms of InLong
JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
Metrics
Affected Vendors & Products
References
History
Wed, 04 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache inlong |
|
CPEs | cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache inlong |
Wed, 28 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 28 May 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 28 May 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/11747 | |
Title | Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read | |
Weaknesses | CWE-502 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-05-28T08:12:27.609Z
Updated: 2025-05-28T13:20:49.864Z
Reserved: 2025-02-27T07:32:40.617Z
Link: CVE-2025-27528

Updated: 2025-05-28T09:04:24.174Z

Status : Analyzed
Published: 2025-05-28T08:15:21.830
Modified: 2025-06-03T15:36:47.120
Link: CVE-2025-27528

No data.