CVE-2023-34434: Apache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath param
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.
The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8130 .
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-34434?
CVE-2023-34434 is a vulnerability in Apache InLong, allowing JDBC URL bypassing by the allowLoadLocalInfileInPath parameter.
What software is affected by CVE-2023-34434?
Apache InLong versions 1.4.0 through 1.7.0 are affected by CVE-2023-34434.
How can an attacker exploit CVE-2023-34434?
An attacker can exploit CVE-2023-34434 by bypassing the current logic and achieving arbitrary file reading.
How can I fix CVE-2023-34434?
To fix CVE-2023-34434, users are advised to upgrade to Apache InLong version 1.8.0 or later.
What is the severity of CVE-2023-34434?
CVE-2023-34434 has a severity level of 7.5 (high).