High severity7.5NVD Advisory· Published Jan 3, 2024· Updated Jun 17, 2026
CVE-2023-51785
CVE-2023-51785
Description
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/9331
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.inlong:manager-pojoMaven | >= 1.5.0, < 1.10.0 | 1.10.0 |
Affected products
3Patches
Vulnerability mechanics
References
6- www.openwall.com/lists/oss-security/2024/01/03/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-crwj-2r3c-gx2gghsaADVISORY
- lists.apache.org/thread/g0yjmtjqvp8bnf1j0tdsk0nhfozjdjnonvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-51785ghsaADVISORY
- github.com/apache/inlong/commit/d674bfe28416aff728eabafc1f6b8bb9ba5a5b8eghsaWEB
- github.com/apache/inlong/pull/9331ghsaWEB
News mentions
0No linked articles in our index yet.