CVE-2022-40955
Deserialization attack in Apache InLong prior to version 1.3.0 allows RCE via JDBC
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 2.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Sep 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLong, potentially leading to Remote Code Execution on the Apache InLong server. Users are advised to upgrade to Apache InLong 1.3.0 or newer.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Apache Software Foundation · Apache InLongWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →