Apache InLong是美国Apache基金会开源的一款大数据处理引擎。 Apache InLong 2.0.0至2.4.0之前版本存在资源管理错误漏洞,该漏洞源于不受控制的资源消耗,可能导致非模板负责人查看模板信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache InLong | 2.0.0< 2.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache InLong | 2.0.0 ~ 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63016 | Apache InLong: Ordinary users can create new packages | |
| CVE-2026-63037 | Apache InLong: Unauthenticated SQL injection in Manager OpenAPI audit alert rule list endp | |
| CVE-2026-63038 | Apache InLong: SQL Injection via String Concatenation Vulnerability Report | |
| CVE-2026-63039 | Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAle | |
| CVE-2026-63040 | Apache InLong: Missing authorization in StreamSource forceDelete | |
| CVE-2026-63042 | Apache InLong: Missing authorization on DataNode management endpoints | |
| CVE-2026-63043 | Apache InLong: Agent path traversal via unvalidated file source path | |
| CVE-2026-63044 | Apache InLong: Authenticated SSRF via POST /api/node/testConnection |
No comments yet