CVE-2023-27296

CVE-2023-27296: Apache InLong: JDBC Deserialization Vulnerability in InLong

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-502 · Unsafe deserialization
Published March 27, 2023
Last update October 23, 2024

CVSS base score

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick [2] to solve it. [1]  https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html [2] https://github.com/apache/inlong/pull/7422 https://github.com/apache/inlong/pull/7422

Key dates

02Disclosure timeline

March 27, 2023 CVE published
October 23, 2024 Record updated

Related vulnerabilities

04Related CVE