Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj32-3pf5-5mv5

Опубликовано: 19 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache InLong Deserialization of Untrusted Data Vulnerability

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.

This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it.

[1] https://github.com/apache/inlong/pull/8814

Пакеты

Наименование

org.apache.inlong:manager-common

maven
Затронутые версииВерсия исправления

>= 1.4.0, < 1.9.0

1.9.0

Наименование

org.apache.inlong:manager-pojo

maven
Затронутые версииВерсия исправления

>= 1.4.0, < 1.9.0

1.9.0

EPSS

Процентиль: 15%
0.00048
Низкий

7.5 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8814

EPSS

Процентиль: 15%
0.00048
Низкий

7.5 High

CVSS3

Дефекты

CWE-502