CVE-2023-34434

CVE-2023-34434: Apache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath param

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-502 · Unsafe deserialization
Published July 25, 2023
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8130 .

Key dates

Disclosure timeline

July 25, 2023 CVE published
February 13, 2025 Record updated