GHSA-fgh3-pwmp-3qw3

Suggest an improvement
Source
https://github.com/advisories/GHSA-fgh3-pwmp-3qw3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-fgh3-pwmp-3qw3/GHSA-fgh3-pwmp-3qw3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fgh3-pwmp-3qw3
Aliases
  • CVE-2024-26579
Published
2024-05-08T15:30:42Z
Modified
2024-12-03T06:08:14.813857Z
Summary
Apache Inlong Deserialization of Untrusted Data vulnerability
Details

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.7.0 through 1.11.0. The attackers can bypass using malicious parameters.

Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it.

[1] https://github.com/apache/inlong/pull/9694

[2]  https://github.com/apache/inlong/pull/9707

Database specific
{
    "nvd_published_at": "2024-05-08T15:15:08Z",
    "cwe_ids": [
        "CWE-502"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-08T19:57:07Z"
}
References

Affected packages

Maven / org.apache.inlong:manager-pojo

Package

Name
org.apache.inlong:manager-pojo
View open source insights on deps.dev
Purl
pkg:maven/org.apache.inlong/manager-pojo

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.7.0
Fixed
1.12.0

Affected versions

1.*

1.7.0
1.8.0
1.9.0
1.10.0
1.11.0