Deserialization of Untrusted Data vulnerability in Apache InLong.
This issue affects Apache InLong: from 1.13.0 through 2.1.0.
This
vulnerability allows attackers to bypass the security mechanisms of InLong
JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/11747
CVE ID: CVE-2025-27528
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.1
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor: Apache Software Foundation
Product: Apache InLong
EPSS Score: 0.11% (probability of being exploited)
EPSS Percentile: 29.97% (scored less or equal to compared to others)
EPSS Date: 2025-06-06 (when was this score calculated)