8.8
CVSSv3

CVE-2023-27296

Published: 27/03/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 up to and including 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick [2] to solve it. [1]  programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html [2] github.com/apache/inlong/pull/7422 github.com/apache/inlong/pull/7422

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache inlong