Apache InLong: Log Injection in Global functions
CVE-2023-43667

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
16 October 2023

Summary

An injection vulnerability in Apache InLong affects versions from 1.4.0 to 1.8.0, allowing attackers to manipulate log records. This manipulation can obscure malicious activities, complicating the audit and tracing processes. Users should upgrade to Apache InLong version 1.9.0 to address this issue.

Affected Version(s)

Apache InLong 1.4.0 <= 1.8.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jayway
.