CVE-2025-27528 – org.apache.inlong:manager-pojo
Package
Manager: maven
Name: org.apache.inlong:manager-pojo
Vulnerable Version: >=1.13.0 <2.2.0
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
EPSS: 0.0009 pctl0.26596
Details
Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/11747
Metadata
Created: 2025-05-28T09:31:27Z
Modified: 2025-05-28T16:04:26Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-98v7-xxxv-hcrh/GHSA-98v7-xxxv-hcrh.json
CWE IDs: ["CWE-502"]
Alternative ID: GHSA-98v7-xxxv-hcrh
Finding: F096
Auto approve: 1