https://seclists.org/oss-sec/2025/q2/172: CVE-2025-27528: Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File ad
Published May 28, 2025
·Updated
Affected Software
1 affected component
Apache Inlong>=1.13.0<=2.1.0
Frequently Asked Questions
1
What is the severity of CVE-2025-27528?
The severity of CVE-2025-27528 is rated as moderate.
2
Which versions of Apache InLong are affected by CVE-2025-27528?
Apache InLong versions 1.13.0 through 2.1.0 are affected by CVE-2025-27528.
3
What is the nature of the vulnerability described in CVE-2025-27528?
CVE-2025-27528 is a deserialization of untrusted data vulnerability that allows attackers to bypass security mechanisms.
4
Can CVE-2025-27528 lead to arbitrary file access?
Yes, CVE-2025-27528 allows for arbitrary file access due to the JDBC vulnerability.
5
How do I fix CVE-2025-27528?
To fix CVE-2025-27528, upgrade Apache InLong to a version later than 2.1.0.