Severity: important

Description:

In versions of Apache InLong prior to 1.3.0, an attacker with
sufficient privileges to specify MySQL JDBC connection URL parameters
and to write arbitrary data to the MySQL database, could cause this
data to be deserialized by Apache InLong, potentially leading to
Remote Code Execution on the Apache InLong server.

Users are advised to upgrade to Apache InLong 1.3.0 or newer.

Credit:

This issue was discovered by 4ra1n of Chaitin Tech.

References:
https://lists.apache.org/thread/r1r34y7bchrpmp9jhfdoohzdmk7pj1q1


-- 
Best wishes,
Charles Zhang

Reply via email to