CVE-2024-26579

CVE-2024-26579: Apache Inlong JDBC Vulnerability

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-502 · Unsafe deserialization
Published May 8, 2024
Last update March 28, 2025

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it. [1] https://github.com/apache/inlong/pull/9694 [2]  https://github.com/apache/inlong/pull/9707

Key dates

Disclosure timeline

May 8, 2024 CVE published
March 28, 2025 Record updated