GHSA-98v7-xxxv-hcrh

Suggest an improvement
Source
https://github.com/advisories/GHSA-98v7-xxxv-hcrh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-98v7-xxxv-hcrh/GHSA-98v7-xxxv-hcrh.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-98v7-xxxv-hcrh
Aliases
  • CVE-2025-27528
Published
2025-05-28T09:31:27Z
Modified
2025-05-28T16:43:07.977667Z
Severity
  • 6.6 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read
Details

Deserialization of Untrusted Data vulnerability in Apache InLong.

This issue affects Apache InLong: from 1.13.0 through 2.1.0.

This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.

[1] https://github.com/apache/inlong/pull/11747

Database specific
{
    "nvd_published_at": "2025-05-28T08:15:21Z",
    "cwe_ids": [
        "CWE-502"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-28T16:04:26Z"
}
References

Affected packages

Maven / org.apache.inlong:manager-pojo

Package

Name
org.apache.inlong:manager-pojo
View open source insights on deps.dev
Purl
pkg:maven/org.apache.inlong/manager-pojo

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.13.0
Fixed
2.2.0

Affected versions

1.*

1.13.0

2.*

2.0.0
2.1.0