VendorsApacheinlongany version
Vulnerabilities

Apache Software Foundation InLong any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

40CVEs
CVE-2023-35088
Apache InLong: SQL injection in audit endpoint
Published 2023-07-25 · Modified
9.8EPSS 0.016
CVE-2023-51784
Apache InLong: Remote Code Execution vulnerability in Apache InLong Manager
Published 2024-01-03 · Modified
9.8EPSS 0.016
CVE-2023-24997
Apache InLong: Jdbc Connection Security Bypass
Published 2023-02-01 · Modified
9.8EPSS 0.013
CVE-2023-31062
Apache InLong: Privilege escalation vulnerability for InLong
Published 2023-05-22 · Modified
9.8EPSS 0.013
CVE-2023-31098
Apache InLong: Weak Password Implementation in InLong
Published 2023-05-22 · Modified
9.8EPSS 0.012
CVE-2024-36268
Apache InLong TubeMQ Client: Remote Code Execution vulnerability
Published 2024-08-02 · Modified
9.8EPSS 0.012
CVE-2024-26579
Apache Inlong JDBC Vulnerability
Published 2024-05-08 · Modified
9.8EPSS 0.011
CVE-2023-43668
Apache InLong: Jdbc Connection Security Bypass in InLong
Published 2023-10-16 · Modified
9.8EPSS 0.010
CVE-2026-63039
Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
Published 2026-08-20 · Analyzed
9.8EPSS 0.007
CVE-2026-63037
Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endpoint
Published 2026-08-20 · Analyzed
9.8EPSS 0.007
CVE-2026-63038
Apache InLong: SQL Injection via String Concatenation Vulnerability Report
Published 2026-08-20 · Analyzed
9.8EPSS 0.007
CVE-2025-27531
Apache InLong: An arbitrary file read vulnerability for JDBC
Published 2025-06-06 · Analyzed
9.8EPSS 0.007
CVE-2023-31066
Apache InLong: Insecure direct object references for inlong sources
Published 2023-05-22 · Modified
9.1EPSS 0.014
CVE-2024-26580
Apache InLong: Logged-in user could exploit an arbitrary file read vulnerability
Published 2024-03-06 · Analyzed
9.1EPSS 0.012
CVE-2023-31065
Apache InLong: Insufficient Session Expiration in InLong
Published 2023-05-22 · Modified
9.1EPSS 0.012
CVE-2025-27528
Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read
Published 2025-05-28 · Analyzed
9.1EPSS 0.007
CVE-2022-40955
Deserialization attack in Apache InLong prior to version 1.3.0 allows RCE via JDBC
Published 2022-09-20 · Modified
8.8EPSS 0.027
CVE-2023-27296
Apache InLong: JDBC Deserialization Vulnerability in InLong
Published 2023-03-27 · Modified
8.8EPSS 0.015
CVE-2026-63046
Apache InLong: Agent Installer — Command Injection to RCE via Default Credentials
Published 2026-08-21 · Analyzed
8.8EPSS 0.007
CVE-2026-63042
Apache InLong: Missing authorization on DataNode management endpoints
Published 2026-08-20 · Analyzed
8.1EPSS 0.006
CVE-2026-63040
Apache InLong: Missing authorization in StreamSource forceDelete
Published 2026-08-20 · Analyzed
8.1EPSS 0.006
CVE-2023-34434
Apache InLong: JDBC URL bypassing by allowLoadLocalInfileInPath param
Published 2023-07-25 · Modified
7.5EPSS 0.017
CVE-2023-31103
Apache InLong: Attackers can change the immutable name and type of cluster
Published 2023-05-22 · Modified
7.5EPSS 0.013
CVE-2023-31206
Apache InLong: Attackers can change the immutable name and type of nodes
Published 2023-05-22 · Modified
7.5EPSS 0.012
CVE-2023-31064
Apache InLong: Insecurity direct object references cancelling applications
Published 2023-05-22 · Modified
7.5EPSS 0.012
CVE-2023-31058
Apache InLong: JDBC URL bypassing by adding blanks
Published 2023-05-22 · Modified
7.5EPSS 0.012
CVE-2023-43667
Apache InLong: Log Injection in Global functions
Published 2023-10-16 · Modified
7.5EPSS 0.012
CVE-2023-31453
Apache InLong: IDOR make users can delete others' subscription
Published 2023-05-22 · Modified
7.5EPSS 0.012
CVE-2023-31454
Apache InLong: IDOR make users can bind any cluster
Published 2023-05-22 · Modified
7.5EPSS 0.012
CVE-2023-24977
Apache InLong: Jdbc Connection causes arbitrary file reading in InLong
Published 2023-02-01 · Modified
7.5EPSS 0.012
CVE-2023-51785
Apache InLong: Arbitrary File Read Vulnerability in Apache InLong Manager
Published 2024-01-03 · Modified
7.5EPSS 0.010
CVE-2023-46227
Apache inlong has an Arbitrary File Read Vulnerability
Published 2023-10-19 · Modified
7.5EPSS 0.010
CVE-2026-63043
Apache InLong: Agent path traversal via unvalidated file source path
Published 2026-08-20 · Analyzed
7.5EPSS 0.008
CVE-2023-34189
Apache InLong: General user can delete and update process
Published 2023-07-25 · Modified
6.5EPSS 0.013
CVE-2025-27522
Apache InLong: JDBC Vulnerability during verification processing
Published 2025-05-28 · Modified
6.5EPSS 0.008
CVE-2025-27526
Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass
Published 2025-05-28 · Analyzed
6.5EPSS 0.008
CVE-2023-43666
Apache InLong: General user Unauthorized access User Management
Published 2023-10-16 · Modified
6.5EPSS 0.004
CVE-2026-63044
Apache InLong: Authenticated SSRF via POST /api/node/testConnection
Published 2026-08-20 · Analyzed
5.4EPSS 0.005
CVE-2026-63016
Apache InLong: Ordinary users can create new packages
Published 2026-08-20 · Analyzed
5.3EPSS 0.006
CVE-2026-63015
Apache InLong: Non-template responsible persons can view template information
Published 2026-08-20 · Analyzed
4.3EPSS 0.006