CVE-2023-27296

CVE-2023-27296: Apache InLong: JDBC Deserialization Vulnerability in InLong

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-502 · Unsafe deserialization
Published March 27, 2023
Last update October 23, 2024

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick [2] to solve it. [1]  https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html [2] https://github.com/apache/inlong/pull/7422 https://github.com/apache/inlong/pull/7422

Key dates

Disclosure timeline

March 27, 2023 CVE published
October 23, 2024 Record updated