Apache InLong: Remote Code Execution vulnerability in Apache InLong Manager
CVE-2023-51784

9.8CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
3 January 2024

Summary

A vulnerability exists in Apache InLong due to improper control of code generation, which may lead to remote code execution. This issue affects versions from 1.5.0 to 1.9.0, allowing malicious actors to exploit the code injection flaw if proper security measures are not in place. Users are strongly encouraged to upgrade to Apache InLong version 1.10.0 to address these security concerns. For a patch, users should refer to the update available in the project's repository.

Affected Version(s)

Apache InLong 1.5.0 <= 1.9.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

X1r0z
.