Skip to main content

Vendor/product archive

apache / inlong CVEs

Beta · best-effort

32 CVEs tagged to apache / inlong13 Critical, 13 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2025-27531

Published Jun 6, 2025

Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-27528

Published May 28, 2025

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-27526

Published May 28, 2025

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerabi…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-27522

Published May 28, 2025

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-36268

Published Aug 2, 2024

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-26579

Published May 8, 2024

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can bypass using malicious parameter…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-26580

Published Mar 6, 2024

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-51785

Published Jan 3, 2024

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack us…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51784

Published Jan 3, 2024

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Cod…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46227

Published Oct 19, 2023

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43668

Published Oct 16, 2023

Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some sensitive params checks will be…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-43667

Published Oct 16, 2023

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 thro…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43666

Published Oct 16, 2023

Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  General user can view all user data lik…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35088

Published Jul 25, 2023

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: fr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34434

Published Jul 25, 2023

Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  The attacker could bypass…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34189

Published Jul 25, 2023

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use g…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31103

Published May 22, 2023

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  Attackers can change th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31101

Published May 22, 2023

Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31098

Published May 22, 2023

Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.  When users change their password…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31066

Published May 22, 2023

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31065

Published May 22, 2023

Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  An old session can be used…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31064

Published May 22, 2023

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31062

Published May 22, 2023

Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.  When the attacker has access…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31454

Published May 22, 2023

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.  The a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31453

Published May 22, 2023

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 32 CVEsPage 1 of 2