CVE-2025-27528 – Apache InLong Deserialization of Untrusted Data Remote File Read Vulnerability

The following table lists the changes that have been made to the
CVE-2025-27528 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • CVE Modified
    by af854a3a-2127-422b-91ae-364da2661108

    May. 28, 2025

    Action Type Old Value New Value
    Added Reference http://www.openwall.com/lists/oss-security/2025/05/28/3
  • New CVE Received
    by [email protected]

    May. 28, 2025

    Action Type Old Value New Value
    Added Description Deserialization of Untrusted Data vulnerability in Apache InLong.

    This issue affects Apache InLong: from 1.13.0 through 2.1.0.

    This
    vulnerability allows attackers to bypass the security mechanisms of InLong
    JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong’s 2.2.0 or cherry-pick [1] to solve it.

    [1] https://github.com/apache/inlong/pull/11747

    Added CWE CWE-502
    Added Reference https://github.com/apache/inlong/pull/11747
    Added Reference https://lists.apache.org/thread/b807rqzgyv4qgvxw3nhkq8tl6g90gqgj
Share the Post:

Related Posts