
CVE-2023-51784 – Apache InLong: Remote Code Execution vulnerability in Apache InLong Manager
https://notcve.org/view.php?id=CVE-2023-51784
03 Jan 2024 — Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/9329 Vulnerabilidad de control inadecuado de generación de código ("inyección de código") en Apache InLong. Este problema afecta a Apache InLong: desde 1.5.0 hasta 1.9.0, lo que podría provoc... • http://www.openwall.com/lists/oss-security/2024/01/03/1 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2023-46227 – Apache inlong has an Arbitrary File Read Vulnerability
https://notcve.org/view.php?id=CVE-2023-46227
19 Oct 2023 — Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8814 Deserialización de la vulnerabilidad de datos no confiables en Apache Software Foundation Apache InLong. Este problema afecta a Apache InLong: desde 1.4.0 hasta 1.8.0, el atacante puede usar ... • https://lists.apache.org/thread/m8txor4f76tmrxksrmc87tw42g57nz33 • CWE-502: Deserialization of Untrusted Data •

CVE-2023-43666 – Apache InLong: General user Unauthorized access User Management
https://notcve.org/view.php?id=CVE-2023-43666
16 Oct 2023 — Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8623 Vulnerabilidad de Verificación Insuficiente de Autenticidad de Datos en Apache InLong. Este problema afecta a Apache InLong: desde la versión 1.4.0 hasta la 1.8.0, el usuario general pu... • https://lists.apache.org/thread/scbgh3ty3xcxm3q33r2t9f42gwwo1why • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2023-43667 – Apache InLong: Log Injection in Global functions
https://notcve.org/view.php?id=CVE-2023-43667
16 Oct 2023 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false records, making it harder to audit and trace malicious activities. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8628 Neutralización Inadecuada de Elementos Especiales utilizados en una vulnerabilidad de Comand... • https://github.com/miguelc49/CVE-2023-43667-3 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-43668 – Apache InLong: Jdbc Connection Security Bypass in InLong
https://notcve.org/view.php?id=CVE-2023-43668
16 Oct 2023 — Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, some sensitive params checks will be bypassed, like "autoDeserizalize","allowLoadLocalInfile".... . Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8604 Vulnerabilidad de Omisión de Autorización a Través de la Clave Controlada por el Usuario en Apache InLong. Este problema afecta a Apache In... • https://lists.apache.org/thread/16gtk7rpdm1rof075ro83fkrnhbzn5sh • CWE-639: Authorization Bypass Through User-Controlled Key •

CVE-2023-35088 – Apache InLong: SQL injection in audit endpoint
https://notcve.org/view.php?id=CVE-2023-35088
25 Jul 2023 — Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8198 Improper Neu... • http://seclists.org/fulldisclosure/2023/Jul/43 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2023-34434 – Apache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath param
https://notcve.org/view.php?id=CVE-2023-34434
25 Jul 2023 — Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8130 . • http://seclists.org/fulldisclosure/2023/Jul/43 • CWE-502: Deserialization of Untrusted Data •

CVE-2023-34189 – Apache InLong: General user can delete and update process
https://notcve.org/view.php?id=CVE-2023-34189
25 Jul 2023 — Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109 to solve it. • http://www.openwall.com/lists/oss-security/2023/07/25/2 • CWE-668: Exposure of Resource to Wrong Sphere •

CVE-2023-31062 – Apache InLong: Privilege escalation vulnerability for InLong
https://notcve.org/view.php?id=CVE-2023-31062
22 May 2023 — Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. When the attacker has access to a valid (but unprivileged) account, the exploit can be executed using Burp Suite by sending a login request and following it with a subsequent HTTP request using the returned cookie. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 https://github.com/apache/inlong/pu... • https://lists.apache.org/thread/btorjbo9o71h22tcvxzy076022hjdzq0 • CWE-269: Improper Privilege Management •

CVE-2023-31064 – Apache InLong: Insecurity direct object references cancelling applications
https://notcve.org/view.php?id=CVE-2023-31064
22 May 2023 — Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application that doesn't belongs to it. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7799 https://github.com/apache/inlong/pull/7799 to solve it. Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apa... • https://lists.apache.org/thread/1osd2k3t3qol2wdsswqtr9gxdkf78n00 • CWE-552: Files or Directories Accessible to External Parties •