cbcvebase.

Apache Inlong vulnerabilities

32 known vulnerabilities affecting apache/inlong.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH13MEDIUM6

Vulnerabilities

Page 1 of 2
CVE-2024-36268P2CRITICALCVSS 9.8≥ 1.10.0, < 1.13.02024-08-02
CVE-2024-36268 [CRITICAL] CWE-94 CVE-2024-36268: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issu Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/10251
nvd
CVE-2025-27531P2CRITICALCVSS 9.8≥ 1.13.0, < 2.1.02025-06-06
CVE-2025-27531 [CRITICAL] CWE-502 CVE-2025-27531: Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommended to upgrade to version 2.1.0, which fixes the issue.
nvd
CVE-2022-40955P2HIGHCVSS 8.8fixed in 1.3.02022-09-20
CVE-2022-40955 [HIGH] CWE-502 CVE-2022-40955: In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLong, potentially leading to Remote Code Execution on the Apache InLong server. Users are advised to upgrade to Apach
nvd
CVE-2024-26580P2CRITICALCVSS 9.1≥ 1.4.0, < 1.11.02024-03-06
CVE-2024-26580 [CRITICAL] CWE-502 CVE-2024-26580: Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: f Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read from an arbitrary file. Users are advised to upgrade to Apache InLong's 1.11.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/9673
nvd
CVE-2023-35088P3CRITICALCVSS 9.8≥ 1.4.0, ≤ 1.7.02023-07-25
CVE-2023-35088 [CRITICAL] CWE-89 CVE-2023-35088: Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL in
nvd
CVE-2023-51784P2CRITICALCVSS 9.8≥ 1.5.0, < 1.10.02024-01-03
CVE-2023-51784 [CRITICAL] CWE-94 CVE-2023-51784: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/9329
nvd
CVE-2025-27528P3CRITICALCVSS 9.1≥ 1.13.0, < 2.2.02025-05-28
CVE-2025-27528 [CRITICAL] CWE-502 CVE-2025-27528: Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and leads to arbitrary file reading. Users are advised to upgrade to Apache InLong's 2.2.0 or cherry-pick [1] to solve it. [1] https://
nvd
CVE-2023-31062P3CRITICALCVSS 9.8≥ 1.2.0, ≤ 1.6.02023-05-22
CVE-2023-31062 [CRITICAL] CWE-269 CVE-2023-31062: Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. When the attacker has access to a valid (but unprivileged) account, the exploit can be executed using Burp Suite by sending a login request and following it with a subsequent HTTP request using the r
nvd
CVE-2024-26579P3CRITICALCVSS 9.8≥ 1.7.0, < 1.12.02024-05-08
CVE-2024-26579 [CRITICAL] CWE-502 CVE-2024-26579: Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: f Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0, the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it. [1] https://github.com/apache/inlong/pull/9694 [2] https://github.com/apac
nvd
CVE-2023-31098P3CRITICALCVSS 9.8≥ 1.1.0, ≤ 1.6.02023-05-22
CVE-2023-31098 [CRITICAL] CWE-521 CVE-2023-31098: Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affe Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's password and access the account. Users are advised to upgrade to Apache InLong
nvd
CVE-2023-24997P3CRITICALCVSS 9.8≥ 1.1.0, ≤ 1.5.02023-02-01
CVE-2023-24997 [CRITICAL] CWE-502 CVE-2023-24997: Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This iss Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223 https://github.com/apache/inlong/pull/7223 to solve it.
nvd
CVE-2023-27296P3HIGHCVSS 8.8≥ 1.1.0, ≤ 1.5.02023-03-27
CVE-2023-27296 [HIGH] CWE-502 CVE-2023-27296: Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It cou Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick [2]
nvd
CVE-2023-31065P3CRITICALCVSS 9.1≥ 1.4.0, ≤ 1.6.02023-05-22
CVE-2023-31065 [CRITICAL] CWE-613 CVE-2023-31065: Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. An old session can be used by an attacker even after the user has been deleted or the password has been changed. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://githu
nvd
CVE-2023-43668P3CRITICALCVSS 9.8≥ 1.4.0, ≤ 1.8.02023-10-16
CVE-2023-43668 [CRITICAL] CWE-639 CVE-2023-43668: Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects A Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, some sensitive params checks will be bypassed, like "autoDeserizalize","allowLoadLocalInfile".... . Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.
nvd
CVE-2023-31066P3CRITICALCVSS 9.1≥ 1.4.0, ≤ 1.6.02023-05-22
CVE-2023-31066 [CRITICAL] CWE-552 CVE-2023-31066: Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apac Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlon
nvd
CVE-2023-34434P3HIGHCVSS 7.5≥ 1.4.0, ≤ 1.7.02023-07-25
CVE-2023-34434 [HIGH] CWE-502 CVE-2023-34434: Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This iss Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/
nvd
CVE-2023-51785P3HIGHCVSS 7.5≥ 1.7.0, ≤ 1.9.02024-01-03
CVE-2023-51785 [HIGH] CWE-502 CVE-2023-51785: Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: f Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/9331
nvd
CVE-2023-46227P3HIGHCVSS 7.5≥ 1.4.0, < 1.9.02023-10-19
CVE-2023-46227 [HIGH] CWE-502 CVE-2023-46227: Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8814
nvd
CVE-2023-31058P3HIGHCVSS 7.5≥ 1.4.0, ≤ 1.6.02023-05-22
CVE-2023-31058 [HIGH] CWE-502 CVE-2023-31058: Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This iss Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers would bypass the 'autoDeserialize' option filtering by adding blanks. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7674 https://
nvd
CVE-2023-43667P3HIGHCVSS 7.5≥ 1.4.0, ≤ 1.8.02023-10-16
CVE-2023-43667 [HIGH] CWE-74 CVE-2023-43667: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') v Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it harder to audit and trace malicious activities. Users are advised to upgrade to Apache InLong's 1
nvd
Apache Inlong vulnerabilities | cvebase