[MAVEN:GHSA-QFF2-8QW7-HCVW] Apache Inlong Code Injection vulnerability

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.

This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve it.

[1]  https://github.com/apache/inlong/pull/10251

Package Affected Version
pkg:maven/org.apache.inlong/tubemq-core >= 1.10.0, < 1.13.0
Package Fixed Version
pkg:maven/org.apache.inlong/tubemq-core = 1.13.0
ID
MAVEN:GHSA-QFF2-8QW7-HCVW
Severity
critical
URL
https://github.com/advisories/GHSA-qff2-8qw7-hcvw
Published
2024-08-02T12:31:43
(6 weeks ago)
Modified
2024-08-02T15:16:26
(6 weeks ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.inlong/tubemq-core org.apache.inlong tubemq-core >= 1.10.0 < 1.13.0
Fixed pkg:maven/org.apache.inlong/tubemq-core org.apache.inlong tubemq-core = 1.13.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...