Apache InLong: Log Injection in Global functions
CVE-2023-43667
7.5HIGH
Summary
An injection vulnerability in Apache InLong affects versions from 1.4.0 to 1.8.0, allowing attackers to manipulate log records. This manipulation can obscure malicious activities, complicating the audit and tracing processes. Users should upgrade to Apache InLong version 1.9.0 to address this issue.
Affected Version(s)
Apache InLong 1.4.0 <= 1.8.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jayway