CyberRota Analysis
AI-GeneratedThe Apache InLong Agent Installer's ModuleManager is vulnerable to command injection due to improper handling of argument delimiters, allowing attackers to execute arbitrary shell commands via the ExcuteLinux.exeCmd() function without proper validation. This vulnerability affects versions 2.0.0 to 2.4.0, posing a significant risk to users who have not upgraded, as it could lead to unauthorized command execution on affected systems. Organizations utilizing Apache InLong should prioritize upgrading to version 2.4.0 or apply the relevant patches to mitigate this risk.
Original NVD Description
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1]/[2] to solve it. [1] https://github.com/apache/inlong/pull/12151 . [2] https://github.com/apache/inlong/pull/12155 .
Related CVEs
Other vulnerabilities affecting the same vendor(s)