Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqr6-3x3f-9wr3

Опубликовано: 06 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Apache InLong SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5.0. By manipulating the "orderType" parameter and the ordering of the returned content using an SQL injection attack, an attacker can extract the username of the   user with ID 1 from the "user" table, one character at a time.  Users are advised to upgrade to Apache InLong's 1.6.0 or cherry-pick PR #7530 to solve it.

Пакеты

Наименование

org.apache.inlong:manager-pojo

maven
Затронутые версииВерсия исправления

>= 1.4.0, < 1.6.0

1.6.0

Наименование

org.apache.inlong:manager-service

maven
Затронутые версииВерсия исправления

>= 1.4.0, < 1.6.0

1.6.0

EPSS

Процентиль: 38%
0.00165
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 5.3
nvd
почти 3 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5.0. By manipulating the "orderType" parameter and the ordering of the returned content using an SQL injection attack, an attacker can extract the username of the   user with ID 1 from the "user" table, one character at a time.  Users are advised to upgrade to Apache InLong's 1.6.0 or cherry-pick [1] to solve it. https://programmer.help/blogs/jdbc-deserialization-vulnerability-learning.html [1] https://github.com/apache/inlong/issues/7529 https://github.com/apache/inlong/issues/7529

EPSS

Процентиль: 38%
0.00165
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-89