CVE-2023-24997

CVE-2023-24997: Apache InLong: Jdbc Connection Security Bypass

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-502 · Unsafe deserialization
Published February 1, 2023
Last update March 26, 2025

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223 https://github.com/apache/inlong/pull/7223  to solve it.

Key dates

Disclosure timeline

February 1, 2023 CVE published
March 26, 2025 Record updated