CVE-2025-27531: Apache InLong: An arbitrary file read vulnerability for JDBC
Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 before 2.1.0,
this issue would allow an authenticated attacker to read arbitrary files by double writing the param.
Users are recommended to upgrade to version 2.1.0, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27531?
CVE-2025-27531 is a critical vulnerability that allows authenticated attackers to read arbitrary files due to deserialization of untrusted data.
How do I fix CVE-2025-27531?
To fix CVE-2025-27531, users should upgrade Apache InLong from versions 1.13.0 to 2.1.0.
What versions are affected by CVE-2025-27531?
CVE-2025-27531 affects Apache InLong versions from 1.13.0 before 2.1.0.
Who can exploit CVE-2025-27531?
CVE-2025-27531 can be exploited by authenticated attackers.
What kind of attack does CVE-2025-27531 enable?
CVE-2025-27531 enables attackers to perform unauthorized file reads by exploiting deserialization flaws.