Apache
Apache Inlong: vulnerabilidades y CVE
Apache Inlong tiene 42 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 16 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE42
Últimos 12 meses10
Críticas16
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-63046 | Alta (8.8) | 0.68% | — | 21 ago 2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no… |
| CVE-2026-63044 | Media (5.4) | 0.50% | — | 20 ago 2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to arbitrary… |
| CVE-2026-63043 | Alta (7.5) | 0.81% | — | 20 ago 2026 | Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's… |
| CVE-2026-63042 | Alta (8.1) | 0.64% | — | 20 ago 2026 | Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong:… |
| CVE-2026-63040 | Alta (8.1) | 0.64% | — | 20 ago 2026 | Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache… |
| CVE-2026-63039 | Crítica (9.8) | 0.69% | — | 20 ago 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection.… |
| CVE-2026-63038 | Crítica (9.8) | 0.69% | — | 20 ago 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and… |
| CVE-2026-63037 | Crítica (9.8) | 0.69% | — | 20 ago 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This… |
| CVE-2026-63016 | Media (5.3) | 0.63% | — | 20 ago 2026 | Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users… |
| CVE-2026-63015 | Media (4.3) | 0.56% | — | 20 ago 2026 | Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade… |
| CVE-2025-27531 | Crítica (9.8) | 0.66% | — | 6 jun 2025 | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing… |
| CVE-2025-27528 | Crítica (9.1) | 0.68% | — | 28 may 2025 | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security mechanisms of InLong JDBC and… |
| CVE-2025-27526 | Media (6.5) | 0.80% | — | 28 may 2025 | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability URLEncdoe and backspace bypass.… |
| CVE-2025-27522 | Media (6.5) | 0.84% | — | 28 may 2025 | Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for CVE-2024-26579. Users are advised to… |
| CVE-2024-36268 | Crítica (9.8) | 1.2% | — | 2 ago 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to… |
| CVE-2024-26579 | Crítica (9.8) | 1.1% | — | 8 may 2024 | Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0, the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache… |
| CVE-2024-26580 | Crítica (9.1) | 1.2% | — | 6 mar 2024 | Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read from an arbitrary file. Users are advised… |
| CVE-2023-51785 | Alta (7.5) | 1.0% | — | 3 ene 2024 | Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to… |
| CVE-2023-51784 | Crítica (9.8) | 1.6% | — | 3 ene 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to… |
| CVE-2023-46227 | Alta (7.5) | 0.97% | — | 19 oct 2023 | Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to… |
| CVE-2023-43668 | Crítica (9.8) | 1.0% | — | 16 oct 2023 | Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, some sensitive params checks will be bypassed, like… |
| CVE-2023-43667 | Alta (7.5) | 1.2% | — | 16 oct 2023 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create… |
| CVE-2023-43666 | Media (6.5) | 0.43% | — | 16 oct 2023 | Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, General user can view all user data like Admin account. Users are advised to… |
| CVE-2023-35088 | Crítica (9.8) | 1.6% | — | 25 jul 2023 | Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. In the… |
| CVE-2023-34434 | Alta (7.5) | 1.7% | — | 25 jul 2023 | Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could bypass the current logic and achieve arbitrary… |
| CVE-2023-34189 | Media (6.5) | 1.3% | — | 25 jul 2023 | Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the… |
| CVE-2023-31103 | Alta (7.5) | 1.3% | — | 22 may 2023 | Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of… |
| CVE-2023-31101 | Media (6.5) | 1.1% | — | 22 may 2023 | Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see… |
| CVE-2023-31098 | Crítica (9.8) | 1.2% | — | 22 may 2023 | Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character… |
| CVE-2023-31066 | Crítica (9.1) | 1.4% | — | 22 may 2023 | Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.