CVE-2023-51785

CVE-2023-51785: Apache InLong: Arbitrary File Read Vulnerability in Apache InLong Manager

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-502 · Unsafe deserialization
Published January 3, 2024
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/9331

Key dates

Disclosure timeline

January 3, 2024 CVE published
February 13, 2025 Record updated