AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2023-35088

CRITICAL · CVSS 9.8 EPSS 1.64%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-07-25 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache, GitHub. It involves a SQL injection risk.

CVE
CVE-2023-35088
Severity
CRITICAL
CVSS
9.8
EPSS
1.64%
Apache GitHub

Original NVD Description

Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8198

Related CVEs

Other vulnerabilities affecting the same vendor(s)