CRITICAL🇵🇱 Wersja polska

CVE-2025-27528

CVSS 9.1v3.1pub. 2025-05-28upd. 2025-06-03

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/11747

🤖 AI Analysis
How it works

The vulnerability stems from improper handling of data deserialization in the InLong JDBC component. An attacker sends crafted malicious data that is deserialized by the application without proper validation of its origin and content. The deserialization mechanism processes input data in a way that allows bypassing built-in JDBC security. As a result, it is possible to force the server to read arbitrary files from the file system.

Impact

An attacker can gain unauthorized access to arbitrary files on the server and compromise system integrity by bypassing Apache InLong JDBC security mechanisms — all without authentication and user interaction.

Mitigation & patch

Apache InLong must be updated immediately to version 2.2.0. Alternatively, you can apply the cherry-pick fix available in the pull request: https://github.com/apache/inlong/pull/11747

Who is affected

Apache InLong in versions 1.13.0 to 2.1.0 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache Inlong

    APP
    Apache
    1.13.0 – 2.2.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2026-63039CRITICAL9.8same product

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache I...

CVE-2026-63038CRITICAL9.8same product

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache I...

CVE-2026-63037CRITICAL9.8same product

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache I...

CVE-2025-27531CRITICAL9.8PL ✓same product

Apache InLong: deserializacja danych — odczyt dowolnych plików

CVE-2024-36268CRITICAL9.8PL ✓same product

Apache InLong — Code Injection umożliwiający zdalne wykonanie kodu (RCE)