CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-26580: Apache InLong: Logged-in user could exploit an arbitrary file read vulnerability

Description

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can

use the specific payload to read from an arbitrary file. Users are advised to upgrade to Apache InLong's 1.11.0 or cherry-pick [1] to solve it.

[1] https://github.com/apache/inlong/pull/9673

Classification

CVE ID: CVE-2024-26580

Affected Products

Vendor: Apache Software Foundation

Product: Apache InLong

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.98% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://lists.apache.org/thread/xvomf66l58x4dmoyzojflvx52gkzcdmk
http://www.openwall.com/lists/oss-security/2024/03/06/1

Timeline