Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability allows attackers to bypass the security mechanisms of InLong
JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
CVSS
No CVSS.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2025/05/28/3 | Mailing List Third Party Advisory |
https://github.com/apache/inlong/pull/11747 | Issue Tracking |
https://lists.apache.org/thread/b807rqzgyv4qgvxw3nhkq8tl6g90gqgj | Vendor Advisory |
Configurations
History
03 Jun 2025, 15:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.apache.org/thread/b807rqzgyv4qgvxw3nhkq8tl6g90gqgj - Vendor Advisory | |
References | () https://github.com/apache/inlong/pull/11747 - Issue Tracking | |
References | () http://www.openwall.com/lists/oss-security/2025/05/28/3 - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:* | |
First Time |
Apache inlong
Apache |
28 May 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-28 08:15
Updated : 2025-06-03 15:36
NVD link : CVE-2025-27528
Mitre link : CVE-2025-27528
JSON object : View
Products Affected
apache
- inlong
CWE
No CWE.