Vulnerabilities > Apache > Inlong

DATE CVE VULNERABILITY TITLE RISK
2024-08-02 CVE-2024-36268 Unspecified vulnerability in Apache Inlong 1.10.0/1.11.0/1.12.0
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution.
network
low complexity
apache
critical
9.8
2024-01-03 CVE-2023-51784 Unspecified vulnerability in Apache Inlong
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/9329
network
low complexity
apache
critical
9.8
2024-01-03 CVE-2023-51785 Unspecified vulnerability in Apache Inlong 1.7.0/1.8.0/1.9.0
Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/9331
network
low complexity
apache
7.5
2023-10-19 CVE-2023-46227 Unspecified vulnerability in Apache Inlong
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8814
network
low complexity
apache
7.5
2023-10-16 CVE-2023-43666 Unspecified vulnerability in Apache Inlong
Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/8623
network
low complexity
apache
6.5
2023-10-16 CVE-2023-43667 Unspecified vulnerability in Apache Inlong
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it harder to audit and trace malicious activities. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8628
network
low complexity
apache
7.5
2023-10-16 CVE-2023-43668 Authorization Bypass Through User-Controlled Key vulnerability in Apache Inlong
Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some sensitive params checks will be bypassed, like "autoDeserizalize","allowLoadLocalInfile".... .   Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/8604
network
low complexity
apache CWE-639
critical
9.8
2023-07-25 CVE-2023-34189 Unspecified vulnerability in Apache Inlong
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.
network
low complexity
apache
6.5
2023-07-25 CVE-2023-34434 Unspecified vulnerability in Apache Inlong
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  The attacker could bypass the current logic and achieve arbitrary file reading.
network
low complexity
apache
7.5
2023-07-25 CVE-2023-35088 Unspecified vulnerability in Apache Inlong
Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8198
network
low complexity
apache
critical
9.8