📦 Inlong

by Apache

🔍 What is Inlong?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-27531

CRITICAL CVSS 9.8 Jun 6, 2025

This vulnerability allows authenticated attackers to read arbitrary files on Apache InLong servers through a deserialization flaw. It affects Apache InLong versions from 1.13.0 up to (but not includin...

CVE-2025-27528

CRITICAL CVSS 9.1 May 28, 2025

This vulnerability allows attackers to exploit insecure deserialization in Apache InLong's JDBC component, enabling arbitrary file reading on affected systems. It affects Apache InLong versions 1.13.0...

CVE-2024-36268

CRITICAL CVSS 9.8 Aug 2, 2024

This CVE describes a code injection vulnerability in Apache InLong that allows attackers to execute arbitrary code remotely. It affects Apache InLong versions 1.10.0 through 1.12.0, potentially impact...

CVE-2024-26579

CRITICAL CVSS 9.8 May 8, 2024

This CVE describes a deserialization vulnerability in Apache InLong that allows attackers to bypass security controls using malicious parameters. Attackers could potentially execute arbitrary code on ...

CVE-2024-26580

CRITICAL CVSS 9.1 Mar 6, 2024

This CVE describes a deserialization vulnerability in Apache InLong that allows attackers to read arbitrary files from the server. The vulnerability affects Apache InLong versions 1.8.0 through 1.10.0...

CVE-2023-51784

CRITICAL CVSS 9.8 Jan 3, 2024

This CVE describes a code injection vulnerability in Apache InLong that allows attackers to execute arbitrary code remotely. It affects Apache InLong versions 1.5.0 through 1.9.0, potentially leading ...

CVE-2023-43668

CRITICAL CVSS 9.8 Oct 16, 2023

CVE-2023-43668 is an authorization bypass vulnerability in Apache InLong that allows attackers to manipulate user-controlled parameters to bypass security checks for sensitive settings like autoDeseri...

CVE-2023-35088

CRITICAL CVSS 9.8 Jul 25, 2023

This CVE describes an SQL injection vulnerability in Apache InLong's toAuditCkSql method where user-controlled parameters (groupId, streamId, auditId, dt) are directly concatenated into SQL queries wi...

CVE-2023-31098

CRITICAL CVSS 9.8 May 22, 2023

Apache InLong versions 1.1.0 through 1.6.0 have weak password requirements that allow users to set simple passwords. Attackers can easily guess these passwords and gain unauthorized access to user acc...

CVE-2023-31065

CRITICAL CVSS 9.1 May 22, 2023

This CVE describes an Insufficient Session Expiration vulnerability in Apache InLong where old sessions remain valid even after user deletion or password changes. Attackers can hijack these sessions t...

CVE-2023-31062

CRITICAL CVSS 9.8 May 22, 2023

This vulnerability allows attackers with valid unprivileged accounts to escalate privileges in Apache InLong. By intercepting login requests and reusing session cookies in subsequent HTTP requests, at...

CVE-2023-46227

HIGH CVSS 7.5 Oct 19, 2023

This vulnerability allows attackers to bypass security controls in Apache InLong by using tab characters to exploit a deserialization flaw. It affects all Apache InLong deployments running versions 1....

CVE-2023-43667

HIGH CVSS 7.5 Oct 16, 2023

This CVE describes a log injection vulnerability in Apache InLong that allows attackers to inject malicious content into log files. This affects Apache InLong versions 1.4.0 through 1.8.0, potentially...

CVE-2023-34434

HIGH CVSS 7.5 Jul 25, 2023

This CVE describes a deserialization vulnerability in Apache InLong that allows attackers to bypass security controls and read arbitrary files. It affects Apache InLong versions 1.4.0 through 1.7.0. O...

CVE-2023-31103

HIGH CVSS 7.5 May 22, 2023

This vulnerability allows attackers to modify the immutable name and type of clusters in Apache InLong, potentially enabling unauthorized configuration changes. It affects Apache InLong versions 1.4.0...

CVE-2023-31453

HIGH CVSS 7.5 May 22, 2023

This vulnerability in Apache InLong allows attackers to delete other users' subscriptions without proper authorization. It affects Apache InLong versions 1.2.0 through 1.6.0, potentially impacting any...

CVE-2023-27296

HIGH CVSS 8.8 Mar 27, 2023

This vulnerability allows authenticated users of Apache InLong to execute arbitrary code through deserialization of untrusted data. It affects Apache InLong versions 1.1.0 through 1.5.0, potentially l...

CVE-2023-24977

HIGH CVSS 7.5 Feb 1, 2023

This CVE describes an out-of-bounds read vulnerability in Apache InLong that could allow attackers to read sensitive information from memory. It affects Apache InLong versions 1.1.0 through 1.5.0. The...

CVE-2025-27526

MEDIUM CVSS 6.5 May 28, 2025

This CVE describes a deserialization vulnerability in Apache InLong that allows attackers to bypass security controls through JDBC URL encoding and backspace character manipulation. It affects Apache ...