CVE-2023-46227

CVE-2023-46227: Apache inlong has an Arbitrary File Read Vulnerability

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-502 · Unsafe deserialization
Published October 19, 2023
Last update September 12, 2024

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8814

Key dates

Disclosure timeline

October 19, 2023 CVE published
September 12, 2024 Record updated