CVE-2023-35088

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-35088
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-35088.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-35088
Aliases
Withdrawn
2024-05-15T05:32:11.777351Z
Published
2023-07-25T08:15:10Z
Modified
2023-11-08T04:12:49.524310Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it.

[1] https://github.com/apache/inlong/pull/8198

References

Affected packages

Git / github.com/apache/inlong

Affected ranges

Type
GIT
Repo
https://github.com/apache/inlong
Events