Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability allows attackers to bypass the security mechanisms of InLong
JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
References
Link | Resource |
---|---|
https://github.com/apache/inlong/pull/11747 | Issue Tracking |
https://lists.apache.org/thread/b807rqzgyv4qgvxw3nhkq8tl6g90gqgj | Vendor Advisory |
http://www.openwall.com/lists/oss-security/2025/05/28/3 | Mailing List Third Party Advisory |
Configurations
History
03 Jun 2025, 15:36
Type | Values Removed | Values Added |
---|---|---|
First Time |
Apache inlong
Apache |
|
References | () https://github.com/apache/inlong/pull/11747 - Issue Tracking | |
References | () https://lists.apache.org/thread/b807rqzgyv4qgvxw3nhkq8tl6g90gqgj - Vendor Advisory | |
References | () http://www.openwall.com/lists/oss-security/2025/05/28/3 - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:* |
28 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
Summary |
|
28 May 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 May 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-28 08:15
Updated : 2025-06-03 15:36
NVD link : CVE-2025-27528
Mitre link : CVE-2025-27528
CVE.ORG link : CVE-2025-27528
JSON object : View
Products Affected
apache
- inlong
CWE
CWE-502
Deserialization of Untrusted Data