Vulnerability Description
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it harder to audit and trace malicious activities. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8628
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Inlong | >= 1.4.0, <= 1.8.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/spnb378g268p1f902fr9kqyph2k8n543Mailing List
- https://lists.apache.org/thread/spnb378g268p1f902fr9kqyph2k8n543Mailing List
FAQ
What is CVE-2023-43667?
CVE-2023-43667 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attack...
How severe is CVE-2023-43667?
CVE-2023-43667 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43667?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Inlong.