PT-2025-23053 · Apache · Apache Inlong

H3H3Qaq

+1

·

Published

2025-02-11

·

Updated

2025-06-02

·

CVE-2025-27528

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache InLong versions 1.13.0 through 2.1.0
Description The issue affects Apache InLong, allowing attackers to bypass its security mechanisms and enabling arbitrary file reading due to a deserialization of untrusted data vulnerability.
Recommendations For Apache InLong versions 1.13.0 through 2.1.0, update to version 2.2.0 to resolve the issue. Alternatively, users can cherry-pick the solution from the provided GitHub pull request.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-06400
CVE-2025-27528
GHSA-98V7-XXXV-HCRH

Affected Products

Apache Inlong