First published: Wed Feb 01 2023(Updated: )
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223 https://github.com/apache/inlong/pull/7223 to solve it.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache InLong | >=1.1.0<=1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24997 is a Deserialization of Untrusted Data vulnerability in Apache InLong, affecting versions 1.1.0 through 1.5.0.
CVE-2023-24997 has a severity rating of 9.8, which is considered critical.
CVE-2023-24997 affects Apache InLong versions 1.1.0 through 1.5.0.
Yes, users are advised to upgrade to the latest version of Apache InLong or apply the fix provided in the following GitHub pull request: https://github.com/apache/inlong/pull/7223.
The Common Weakness Enumeration (CWE) for CVE-2023-24997 is CWE-502.