We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-30465

Apache InLong: SQL injection in apache inLong 1.5.0



Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5.0. By manipulating the "orderType" parameter and the ordering of the returned content using an SQL injection attack, an attacker can extract the username of the   user with ID 1 from the "user" table, one character at a time.  Users are advised to upgrade to Apache InLong's 1.6.0 or cherry-pick [1] to solve it. https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html [1] https://github.com/apache/inlong/issues/7529 https://github.com/apache/inlong/issues/7529

Reserved 2023-04-10 | Published 2023-04-11 | Updated 2025-02-13 | Assigner apache

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

1.4.0
affected

Credits

escape Wang finder

References

lists.apache.org/thread/mrh4nr3jrlbj6nxkn4q8hddbfh1pnok0 vendor-advisory

www.openwall.com/lists/oss-security/2023/04/11/2

cve.org (CVE-2023-30465)

nvd.nist.gov (CVE-2023-30465)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2023-30465

Support options

Helpdesk Chat, Email, Knowledgebase