Apache InLong: Remote Code Execution vulnerability in Apache InLong Manager
CVE-2023-51784
9.8CRITICAL
Summary
A vulnerability exists in Apache InLong due to improper control of code generation, which may lead to remote code execution. This issue affects versions from 1.5.0 to 1.9.0, allowing malicious actors to exploit the code injection flaw if proper security measures are not in place. Users are strongly encouraged to upgrade to Apache InLong version 1.10.0 to address these security concerns. For a patch, users should refer to the update available in the project's repository.
Affected Version(s)
Apache InLong 1.5.0 <= 1.9.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
X1r0z