CVE-2023-27296
Apache InLong vulnerable to JDBC Deserialization of Untrusted Data
8.8
HIGH
CVSS 3.1
EPSS 1.5%
Description
Apache InLong versions from 1.1.0 through 1.5.0 are vulnerable to Java Database Connectivity (JDBC) deserialization of untrusted data from the MySQL JDBC URL in MySQLDataNode. It could be triggered by authenticated users of InLong. This has been patched in version 1.6.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick the [patch](https://github.com/apache/inlong/pull/7422) to solve it.
How to fix CVE-2023-27296
To remediate CVE-2023-27296, upgrade the affected package to a fixed version below.
- —upgrade to 1.6.0 or later
Is CVE-2023-27296 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 1.1.0, < 1.6.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |