First published: Tue Sep 20 2022(Updated: )
In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLong, potentially leading to Remote Code Execution on the Apache InLong server. Users are advised to upgrade to Apache InLong 1.3.0 or newer.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache InLong | <1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40955 is a vulnerability in Apache InLong versions prior to 1.3.0 that could allow an attacker to execute remote code.
The severity of CVE-2022-40955 is high, with a CVSS score of 8.8.
CVE-2022-40955 allows an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and write arbitrary data to the MySQL database, which can then be deserialized by Apache InLong, potentially leading to remote code execution.
Yes, Apache InLong versions prior to 1.3.0 are affected by CVE-2022-40955.
To fix CVE-2022-40955, upgrade Apache InLong to version 1.3.0 or later.