Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommended to upgrade to version 2.1.0, which fixes the issue.
History

Mon, 23 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache inlong
CPEs cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache inlong

Tue, 10 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 15:45:00 +0000

Type Values Removed Values Added
References

Fri, 06 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommended to upgrade to version 2.1.0, which fixes the issue.
Title Apache InLong: An arbitrary file read vulnerability for JDBC
Weaknesses CWE-502
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-06-06T14:55:28.516Z

Updated: 2025-06-10T15:30:50.280Z

Reserved: 2025-02-28T03:26:44.566Z

Link: CVE-2025-27531

cve-icon Vulnrichment

Updated: 2025-06-06T15:04:02.312Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-06T15:15:23.883

Modified: 2025-06-23T14:24:00.320

Link: CVE-2025-27531

cve-icon Redhat

No data.