Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability allows attackers to bypass the security mechanisms of InLong
JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
References
Link | Resource |
---|---|
https://github.com/apache/inlong/pull/11747 | Issue Tracking |
https://lists.apache.org/thread/b807rqzgyv4qgvxw3nhkq8tl6g90gqgj | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2025/05/28/3 | Mailing List Third Party Advisory |
Configurations
History
03 Jun 2025, 15:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/apache/inlong/pull/11747 - Issue Tracking | |
References | () https://lists.apache.org/thread/b807rqzgyv4qgvxw3nhkq8tl6g90gqgj - Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2025/05/28/3 - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:* | |
First Time |
Apache
Apache inlong |
28 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
28 May 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 May 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-28 08:15
Updated : 2025-06-03 15:36
NVD link : CVE-2025-27528
Mitre link : CVE-2025-27528
CVE.ORG link : CVE-2025-27528
JSON object : View
Products Affected
apache
- inlong
CWE
CWE-502
Deserialization of Untrusted Data