CVE-2023-31058

CVE-2023-31058: Apache InLong: JDBC URL bypassing by adding blanks

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-502 · Unsafe deserialization
Published May 22, 2023
Last update October 10, 2024

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers would bypass the 'autoDeserialize' option filtering by adding blanks. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick  https://github.com/apache/inlong/pull/7674 https://github.com/apache/inlong/pull/7674 to solve it.

Key dates

Disclosure timeline

May 22, 2023 CVE published
October 10, 2024 Record updated