{"cve":{"cve_id":"CVE-2025-27528","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00576,"epss_percentile":0.42955,"epss_as_of":"2026-06-23","description":"Deserialization of Untrusted Data vulnerability in Apache InLong.\n\nThis issue affects Apache InLong: from 1.13.0 through 2.1.0. \n\nThis\nvulnerability allows attackers to bypass the security mechanisms of InLong\nJDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/11747","published_at":"2025-05-28T08:12:27.609000Z","last_modified_at":null,"cvss_v3_score":9.1,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cvss_v3_severity":"CRITICAL","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":["CWE-502"],"nvd_references":["https://lists.apache.org/thread/b807rqzgyv4qgvxw3nhkq8tl6g90gqgj","https://github.com/apache/inlong/pull/11747"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:26:09.014844Z"},"effective_severity":"CRITICAL","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"apache-software-foundation","vendor_name":"Apache Software Foundation","product_slug":"apache-inlong","product_name":"Apache InLong","version_start":"1.13.0","version_start_inclusive":true,"version_end":"2.1.0","version_end_inclusive":true,"cpe23_uri":"cve5:apache-software-foundation:apache-inlong:1.13.0:2.1.0"}],"exploit_refs":[],"news":[],"references":[{"url":"https://lists.apache.org/thread/b807rqzgyv4qgvxw3nhkq8tl6g90gqgj","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://github.com/apache/inlong/pull/11747","source_type":"PATCH","tags":["patch"]}],"timeline":[{"type":"published","at":"2025-05-28T08:12:27.609000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:44:19.897881Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:44:19.897881Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:44:19.897881Z","label":"CVSS score revised","source":"cvelistv5"}]}