PT-2023-2169 · Apache · Apache Inlong
S3Gundo
+1
·
Published
2023-02-01
·
Updated
2025-03-26
·
CVE-2023-24997
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache InLong versions 1.1.0 through 1.5.0
Description
The issue is related to the deserialization of untrusted data, which can allow a remote attacker to impact the confidentiality, integrity, and availability of the system. Users are advised to take action to resolve the issue.
Recommendations
For Apache InLong versions 1.1.0 through 1.5.0, upgrade to the latest version of Apache InLong or cherry-pick https://github.com/apache/inlong/pull/7223 to solve the issue.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Inlong