Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2022-40955 Details
Description
In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLong, potentially leading to Remote Code Execution on the Apache InLong server. Users are advised to upgrade to Apache InLong 1.3.0 or newer.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2025Exploitation: NoneAutomatable: NoTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.apache.org/thread/r1r34y7bchrpmp9jhfdoohzdmk7pj1q1 | CVE | Issue TrackingMailing ListPatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2022/09/22/5 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/r1r34y7bchrpmp9jhfdoohzdmk7pj1q1 | [email protected] | Issue TrackingMailing ListPatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2022/09/22/5 | [email protected] | Mailing ListThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache inlong | < 1.3.0 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 21, 2022 | Modified Analysis | [email protected] |
| Dec 21, 2022 | CVE Modified | [email protected] |
| Sep 28, 2022 | Modified Analysis | [email protected] |
| Sep 22, 2022 | CVE Modified | [email protected] |
| Sep 21, 2022 | Initial Analysis | [email protected] |