PT-2025-23053 · Apache · Apache Inlong

·

CVE-2025-27528

·

Published

2025-02-11

·

Updated

2025-06-02

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache InLong versions 1.13.0 through 2.1.0
Description The issue affects Apache InLong, allowing attackers to bypass its security mechanisms and enabling arbitrary file reading due to a deserialization of untrusted data vulnerability.
Recommendations For Apache InLong versions 1.13.0 through 2.1.0, update to version 2.2.0 to resolve the issue. Alternatively, users can cherry-pick the solution from the provided GitHub pull request.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06400
CVE-2025-27528
GHSA-98V7-XXXV-HCRH

Affected Products

Apache Inlong