{"id":"GHSA-p2gx-4434-pf6g","summary":"Apache InLong: Logged-in user could exploit an arbitrary file read vulnerability","details":"Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can \n\nuse the specific payload to read from an arbitrary file. Users are advised to upgrade to Apache InLong's 1.11.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/9673","aliases":["CVE-2024-26580"],"modified":"2024-08-02T14:17:55.188907Z","published":"2024-03-06T12:30:29Z","database_specific":{"github_reviewed_at":"2024-03-06T17:05:57Z","nvd_published_at":"2024-03-06T12:15:45Z","cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26580"},{"type":"WEB","url":"https://github.com/apache/inlong/pull/9673"},{"type":"WEB","url":"https://github.com/apache/inlong/commit/1b63af3e1f208602f60b5ce19af7413443c3027c"},{"type":"PACKAGE","url":"https://github.com/apache/inlong"},{"type":"WEB","url":"https://lists.apache.org/thread/xvomf66l58x4dmoyzojflvx52gkzcdmk"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/03/06/1"}],"affected":[{"package":{"name":"org.apache.inlong:manager-common","ecosystem":"Maven","purl":"pkg:maven/org.apache.inlong/manager-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.8.0"},{"fixed":"1.11.0"}]}],"versions":["1.10.0","1.8.0","1.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-p2gx-4434-pf6g/GHSA-p2gx-4434-pf6g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}