CVE-2023-35088 – org.apache.inlong:manager-service
Package
Manager: maven
Name: org.apache.inlong:manager-service
Vulnerable Version: >=1.4.0 <1.8.0
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00513 pctl0.65577
Details
SQL injection in audit endpoint Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8198
Metadata
Created: 2023-07-25T09:30:18Z
Modified: 2025-02-13T19:01:55Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-r5pv-7g89-cxmc/GHSA-r5pv-7g89-cxmc.json
CWE IDs: ["CWE-89"]
Alternative ID: GHSA-r5pv-7g89-cxmc
Finding: F297
Auto approve: 1