Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.
This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/8814
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2762 | Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8814 |
Github GHSA |
GHSA-jj32-3pf5-5mv5 | Apache InLong Deserialization of Untrusted Data Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-12T20:13:07.162Z
Reserved: 2023-10-19T02:16:38.521Z
Link: CVE-2023-46227
Updated: 2024-08-02T20:37:40.117Z
Status : Modified
Published: 2023-10-19T10:15:10.090
Modified: 2024-11-21T08:28:06.950
Link: CVE-2023-46227
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA