Lucene search

K
vulnrichmentApacheVULNRICHMENT:CVE-2023-43667
HistoryOct 16, 2023 - 8:08 a.m.

CVE-2023-43667 Apache InLong: Log Injection in Global functions

2023-10-1608:08:01
CWE-74
apache
github.com
apache inlong
sql injection
vulnerability
version 1.4.0
version 1.8.0
upgrade

EPSS

0.001

Percentile

38.5%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Improper Neutralization of Special Elements in Output Used by a Downstream Component (β€˜Injection’) vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it harder to audit
and trace malicious activities.Β Users are advised to upgrade to Apache InLong’s 1.9.0 or cherry-pick [1] to solve it.

[1] https://github.com/apache/inlong/pull/8628

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*"
    ],
    "vendor": "apache",
    "product": "inlong",
    "versions": [
      {
        "status": "affected",
        "version": "1.4.0",
        "versionType": "semver",
        "lessThanOrEqual": "1.8.0"
      }
    ],
    "defaultStatus": "unknown"
  }
]

EPSS

0.001

Percentile

38.5%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-43667