Apache InLong Vulnerability Could Lead to Remote Code Execution
CVE-2024-36268

9.8CRITICAL

Key Information:

Vendor

Apache

Status
Vendor
CVE Published:
2 August 2024

Badges

đź“° News Worthy

What is CVE-2024-36268?

A flaw has been identified in Apache InLong versions 1.10.0 to 1.12.0 that allows for improper control of code generation, classified as a code injection vulnerability. This could potentially enable an attacker to execute arbitrary code remotely. Users operating these affected versions must upgrade to version 1.13.0 or apply patches provided to mitigate the security risks associated with this vulnerability. For additional information, refer to the detailed discussions in the Apache mailing lists.

News Articles

CVE-2024-36268: Critical Flaw Found In Apache InLong

Given the critical nature of CVE-2024-36268 and reliance on Apache InLong across various industries, the immediate action cannot be overstated.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź“°

    First article discovered by The Cyber Express

  • Vulnerability published

.