https://seclists.org/oss-sec/2025/q1/166: CVE-2025-27531: Apache InLong: An arbitrary file ad vulnerability for JDBC
Published Feb 28, 2025
·Updated
Affected Software
1 affected component
Apache Inlong<2.1.0
Frequently Asked Questions
1
What is the severity of CVE-2025-27531?
The severity of CVE-2025-27531 is classified as moderate.
2
What versions are affected by CVE-2025-27531?
CVE-2025-27531 affects Apache InLong versions from 1.13.0 before 2.1.0.
3
What exploit does CVE-2025-27531 facilitate?
CVE-2025-27531 allows for a deserialization of untrusted data vulnerability, leading to potential arbitrary file access.
4
How do I fix CVE-2025-27531?
To fix CVE-2025-27531, it is recommended to upgrade Apache InLong to version 2.1.0 or later.
5
What can happen if I do not address CVE-2025-27531?
If not addressed, CVE-2025-27531 could allow attackers to bypass security controls by exploiting the double writing of parameters.