Description

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.

This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it.

[1] https://github.com/apache/inlong/pull/8814

Published: 2023-10-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-2762 Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8814
Github GHSA Github GHSA GHSA-jj32-3pf5-5mv5 Apache InLong Deserialization of Untrusted Data Vulnerability
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-12T20:13:07.162Z

Reserved: 2023-10-19T02:16:38.521Z

Link: CVE-2023-46227

cve-icon Vulnrichment

Updated: 2024-08-02T20:37:40.117Z

cve-icon NVD

Status : Modified

Published: 2023-10-19T10:15:10.090

Modified: 2024-11-21T08:28:06.950

Link: CVE-2023-46227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses