SQL Injection in Apache InLong
High severity
GitHub Reviewed
Published
Oct 16, 2023
to the GitHub Advisory Database
•
Updated Sep 27, 2024
Description
Published by the National Vulnerability Database
Oct 16, 2023
Published to the GitHub Advisory Database
Oct 16, 2023
Reviewed
Oct 17, 2023
Last updated
Sep 27, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false records, making it harder to audit
and trace malicious activities. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it.
[1] apache/inlong#8628
References