Apache · Apache Inlong · CVE-2023-24997
**Name of the Vulnerable Software and Affected Versions**
Apache InLong versions 1.1.0 through 1.5.0
**Description**
The issue is related to the deserialization of untrusted data, which can allow a remote attacker to impact the confidentiality, integrity, and availability of the system. Users are advised to take action to resolve the issue.
**Recommendations**
For Apache InLong versions 1.1.0 through 1.5.0, upgrade to the latest version of Apache InLong or cherry-pick https://github.com/apache/inlong/pull/7223 to solve the issue.