https://seclists.org/oss-sec/2023/q3/65: CVE-2023-34434: Apache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath param
Published Jul 25, 2023
·Updated
Affected Software
1 affected component
Apache Inlong>=1.4.0<=1.7.0
Frequently Asked Questions
1
What is the severity of CVE-2023-34434?
The severity of CVE-2023-34434 is classified as important.
2
Which versions of Apache InLong are affected by CVE-2023-34434?
CVE-2023-34434 affects Apache InLong versions 1.4.0 through 1.7.0.
3
What type of vulnerability is CVE-2023-34434?
CVE-2023-34434 is classified as a deserialization of untrusted data vulnerability.
4
How do I fix CVE-2023-34434?
To fix CVE-2023-34434, upgrade Apache InLong to a version beyond 1.7.0.
5
What exploit could an attacker use with CVE-2023-34434?
An attacker could bypass the current logic and achieve arbitrary code execution due to CVE-2023-34434.