GHSA-jj32-3pf5-5mv5
Dashboard / Vulnerabilities / GHSA-jj32-3pf5-5mv5
Summary: Apache InLong Deserialization of Untrusted Data Vulnerability
Details: Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8814
References: https://nvd.nist.gov/vuln/detail/CVE-2023-46227, https://github.com/apache/inlong/pull/8814, https://github.com/apache/inlong, https://lists.apache.org/thread/m8txor4f76tmrxksrmc87tw42g57nz33
Affected packages
Package
Name: org.apache.inlong:manager-common
Purl: pkg:maven/org.apache.inlong/manager-common
Affected ranges
Type: ECOSYSTEM
Events:
