CVE Database
/

CVE-2024-36268

Back to search

CVE-2024-36268

Published: Aug 2, 2024

Modified: Aug 22, 2024

PUBLISHED

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/10251

VendorProductVersions

Apache Software Foundation

Apache InLong TubeMQ Client

affected
1.10.0 - <= 1.12.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now