PT-2023-21058 · Apache+1 · Apache Inlong+1
Escape Wang
·
Publicado
2023-03-27
·
Atualizado
2024-10-23
·
CVE-2023-27296
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache InLong versions 1.1.0 through 1.5.0
Description
The issue is related to the deserialization of untrusted data in Apache InLong, which could be triggered by authenticated users. This vulnerability affects the MySQLDataNode due to the deserialization of untrusted data from the MySQL JDBC URL.
Recommendations
For Apache InLong versions 1.1.0 through 1.5.0, users are advised to upgrade to Apache InLong's latest version or cherry-pick the patch to solve the issue. As a temporary workaround, consider restricting access to the MySQLDataNode to minimize the risk of exploitation.
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Inlong
Mysql Server