Lucene search

K
osvGoogleOSV:CVE-2023-34434
HistoryJul 25, 2023 - 8:15 a.m.

CVE-2023-34434

2023-07-2508:15:10
Google
osv.dev
7
cve-2023-34434
apache software foundation
arbitrary file reading

AI Score

7.2

Confidence

High

EPSS

0.004

Percentile

73.7%

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.

The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong’s 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8130 .

AI Score

7.2

Confidence

High

EPSS

0.004

Percentile

73.7%