This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability allows attackers to bypass the security mechanisms of InLong
JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-16327 | Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read | 
  Github GHSA | 
                GHSA-98v7-xxxv-hcrh | Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Apache
         Apache inlong  | 
|
| CPEs | cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Apache
         Apache inlong  | 
Wed, 28 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        cvssV3_1
         
 
  | 
Wed, 28 May 2025 09:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Wed, 28 May 2025 08:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/11747 | |
| Title | Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read | |
| Weaknesses | CWE-502 | |
| References | 
         | 
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-05-28T13:20:49.864Z
Reserved: 2025-02-27T07:32:40.617Z
Link: CVE-2025-27528
Updated: 2025-05-28T09:04:24.174Z
Status : Analyzed
Published: 2025-05-28T08:15:21.830
Modified: 2025-06-03T15:36:47.120
Link: CVE-2025-27528
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA