{"id":"CVE-2024-36268","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-36268","summary":"Apache Inlong Code Injection vulnerability","details":"Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.\n\nThis issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/10251","published":"2024-08-02T12:31:43Z","modified":"2024-08-22T21:52:38.340200Z","cvss":{"score":7.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.inlong:tubemq-core","fixedVersion":"1.13.0"}],"fix":{"url":"https://github.com/apache/inlong/pull/10251","label":"apache/inlong#10251"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36268"},{"type":"WEB","url":"https://github.com/apache/inlong/pull/10251"},{"type":"WEB","url":"https://github.com/apache/inlong/commit/85fc8b02e69badc5103fadb77559a921c788537a"},{"type":"WEB","url":"https://lists.apache.org/thread/1w1yp1bg5sjvn46dszkf00tz1vfs0frc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-22T21:52:38.340200Z"}}