GHSA-c3rh-f2w5-fghm
Dashboard / Vulnerabilities / GHSA-c3rh-f2w5-fghm
Summary: Apache InLong Deserialization of Untrusted Data Vulnerability
Details: Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers would bypass the `autoDeserialize` option filtering by adding blanks. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7674 to solve it.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-31058, https://github.com/apache/inlong/pull/7674, https://github.com/apache/inlong, https://lists.apache.org/thread/bkcgbn9l61croxfyspf7xd42qb189s3z
Affected packages
Package
Name: org.apache.inlong:manager-pojo
Purl: pkg:maven/org.apache.inlong/manager-pojo
Affected ranges
Type: ECOSYSTEM
Events:
