CVE-2025-27528: Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27528?
CVE-2025-27528 is classified as a critical severity vulnerability due to its potential for arbitrary file reading.
How do I fix CVE-2025-27528?
To mitigate the risk of CVE-2025-27528, upgrade Apache InLong to version 2.1.1 or later.
What versions of Apache InLong are affected by CVE-2025-27528?
CVE-2025-27528 affects Apache InLong versions from 1.13.0 through 2.1.0.
What type of vulnerability is CVE-2025-27528?
CVE-2025-27528 is identified as a deserialization of untrusted data vulnerability.
What are the potential impacts of CVE-2025-27528?
The vulnerability allows attackers to bypass security mechanisms in InLong JDBC and leads to the risk of arbitrary file reading.