CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-26579: Apache Inlong JDBC Vulnerability

Description

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0, 

the attackers can bypass using malicious parameters.

Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it.

[1] https://github.com/apache/inlong/pull/9694

[2]  https://github.com/apache/inlong/pull/9707

Classification

CVE ID: CVE-2024-26579

Affected Products

Vendor: Apache Software Foundation

Product: Apache InLong

Exploit Prediction Scoring System (EPSS)

EPSS Score: 1.38% (probability of being exploited)

EPSS Percentile: 86.45% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://lists.apache.org/thread/d2hndtvh6bll4pkl91o2oqxyynhr54k3
https://github.com/advisories/GHSA-fgh3-pwmp-3qw3
http://www.openwall.com/lists/oss-security/2024/05/09/2

Timeline