Skip to content

[Bug]A JDBC deserialization vulnerability #8126

@springkill

Description

@springkill

What happened

A JDBC deserialization vulnerability in Apache Inlong <= 1.7.0

What you expected to happen

No filter

How to reproduce

Just send an url with autoDeserialize

Environment

All

InLong version

1.7.0

InLong Component

InLong Manager

Are you willing to submit PR?

  • Yes, I am willing to submit a PR!

Code of Conduct

Metadata

Metadata

Assignees

No one assigned

    Labels

    type/bugSomething is wrong

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions