CVE-2024-26580

CVE-2024-26580: Apache InLong: Logged-in user could exploit an arbitrary file read vulnerability

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-502 · Unsafe deserialization
Published March 6, 2024
Last update February 13, 2025

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read from an arbitrary file. Users are advised to upgrade to Apache InLong's 1.11.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/9673

Key dates

Disclosure timeline

March 6, 2024 CVE published
February 13, 2025 Record updated