logo

CVE-2025-27528 org.apache.inlong:manager-pojo

Package

Manager: maven
Name: org.apache.inlong:manager-pojo
Vulnerable Version: >=1.13.0 <2.2.0

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U

EPSS: 0.0009 pctl0.26596

Details

Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/11747

Metadata

Created: 2025-05-28T09:31:27Z
Modified: 2025-05-28T16:04:26Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-98v7-xxxv-hcrh/GHSA-98v7-xxxv-hcrh.json
CWE IDs: ["CWE-502"]
Alternative ID: GHSA-98v7-xxxv-hcrh
Finding: F096
Auto approve: 1