CVE-2023-24977: Apache InLong: Jdbc Connection causes arbitrary file reading in InLong
Published Feb 1, 2023
·Updated
Out-of-bounds Read vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7214 https://github.com/apache/inlong/pull/7214 to solve it.
Affected Software
1 affected component
Apache Inlong>=1.1.0<=1.5.0
Event History
Feb 1, 2023
CVE Published
via MITRE·09:09 AM
Data Sourced
via MITRE·09:09 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-24977.
2
What is the vulnerability severity?
The vulnerability severity is high, with a CVSS score of 7.5.
3
Which software is affected by this vulnerability?
The Apache InLong software versions 1.1.0 through 1.5.0 are affected.
4
How can I fix this vulnerability?
Upgrade to the latest version of Apache InLong or apply the relevant patches.
5
Where can I find more information about this vulnerability?
More information can be found at the following reference: https://lists.apache.org/thread/ggozxorctn3tdll7bgmpwwcbjnd0s6w7