CVE-2025-27531

Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommended to upgrade to version 2.1.0, which fixes the issue.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*

History

23 Jun 2025, 14:24

Type Values Removed Values Added
CPE cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*
First Time Apache inlong
Apache
References () http://www.openwall.com/lists/oss-security/2025/02/28/2 - () http://www.openwall.com/lists/oss-security/2025/02/28/2 - Mailing List, Vendor Advisory
References () https://lists.apache.org/thread/r62lkqrr739wvcb60j6ql6q63rh4bxx5 - () https://lists.apache.org/thread/r62lkqrr739wvcb60j6ql6q63rh4bxx5 - Vendor Advisory, Mailing List

10 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-502

06 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 15:15

Updated : 2025-06-23 14:24


NVD link : CVE-2025-27531

Mitre link : CVE-2025-27531


JSON object : View

Products Affected

apache

  • inlong
CWE

No CWE.