Severity: important

Description:

Deserialization of Untrusted Data vulnerability in Apache Software
Foundation Apache InLong.

It could be triggered by authenticated users of InLong, you could
refer to [1] to know more about this vulnerability.

This issue affects Apache InLong: from 1.1.0 through 1.5.0.  Users are
advised to upgrade to Apache InLong's latest version or cherry-pick
[2] to solve it.



[1] 
https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html
[2] https://github.com/apache/inlong/pull/7422
https://github.com/apache/inlong/pull/7422

Credit:

escape Wang (finder)

References:

https://https://inlong.apache.orghttps://www.cve.org/CVERecord?id=CVE-2023-27296



Best wishes,
Charles Zhang
from Apache InLong

Reply via email to