CVE-2025-27531
- EPSS 0.39%
- Published 06.06.2025 15:15:23
- Last modified 23.06.2025 14:24:00
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are rec...
CVE-2025-27528
- EPSS 0.14%
- Published 28.05.2025 08:15:21
- Last modified 03.06.2025 15:36:47
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading...
CVE-2025-27526
- EPSS 0.13%
- Published 28.05.2025 08:15:21
- Last modified 03.06.2025 15:36:56
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability URLEncdoe and backspace bypass. Users are advised to upgrade to Ap...
CVE-2025-27522
- EPSS 0.18%
- Published 28.05.2025 08:15:21
- Last modified 03.06.2025 14:09:41
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for CVE-2024-26579. Users are advised to upgrade to Apache InLong's 2.2.0 ...
CVE-2024-36268
- EPSS 2.65%
- Published 02.08.2024 10:16:00
- Last modified 21.11.2024 09:21:57
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0...
CVE-2024-26579
- EPSS 0.32%
- Published 08.05.2024 15:15:08
- Last modified 28.03.2025 19:15:20
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0, the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pi...
CVE-2024-26580
- EPSS 0.23%
- Published 06.03.2024 12:15:45
- Last modified 07.05.2025 15:45:54
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read from an arbitrary file. Users are advised to upgrade to Apache InLong's...
CVE-2023-51785
- EPSS 0.3%
- Published 03.01.2024 10:15:09
- Last modified 13.02.2025 18:15:53
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache InLong's 1.10....
CVE-2023-51784
- EPSS 7.08%
- Published 03.01.2024 10:15:09
- Last modified 16.05.2025 16:15:27
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.10.0 or ...
CVE-2023-46227
- EPSS 0.04%
- Published 19.10.2023 10:15:10
- Last modified 21.11.2024 08:28:06
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or che...