PT-2023-21058 · Apache+1 · Apache Inlong+1

Escape Wang

·

Publicado

2023-03-27

·

Atualizado

2024-10-23

·

CVE-2023-27296

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache InLong versions 1.1.0 through 1.5.0
Description The issue is related to the deserialization of untrusted data in Apache InLong, which could be triggered by authenticated users. This vulnerability affects the MySQLDataNode due to the deserialization of untrusted data from the MySQL JDBC URL.
Recommendations For Apache InLong versions 1.1.0 through 1.5.0, users are advised to upgrade to Apache InLong's latest version or cherry-pick the patch to solve the issue. As a temporary workaround, consider restricting access to the MySQLDataNode to minimize the risk of exploitation.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-27296
GHSA-GPQQ-59RP-3C3W

Produtos afetados

Apache Inlong
Mysql Server