CyberRota Analysis
AI-GeneratedApache InLong versions prior to 2.4.0 are vulnerable to SQL injection due to improper neutralization of special elements in parameters such as dbName, tableName, schemaName, and username. This vulnerability allows attackers to execute arbitrary SQL commands, potentially compromising the integrity and confidentiality of the database. Organizations using affected versions should prioritize upgrading to 2.4.0 or applying the recommended fix to mitigate this risk.
Original NVD Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/issues/12135 .
Related CVEs
Other vulnerabilities affecting the same vendor(s)