https://seclists.org/oss-sec/2023/q4/112: CVE-2023-43667: Apache InLong: Log Injection in Global functions
Published Oct 16, 2023
·Updated
Affected Software
1 affected component
Apache Inlong>=1.4.0<=1.8.0
Frequently Asked Questions
1
What is the severity of CVE-2023-43667?
The severity of CVE-2023-43667 is classified as moderate.
2
Which versions of Apache InLong are affected by CVE-2023-43667?
Apache InLong versions 1.4.0 through 1.8.0 are affected by CVE-2023-43667.
3
What type of vulnerability is CVE-2023-43667?
CVE-2023-43667 is an SQL injection vulnerability due to improper neutralization of special elements.
4
How can I mitigate CVE-2023-43667 in my Apache InLong deployment?
To mitigate CVE-2023-43667, upgrade Apache InLong to a version that is not vulnerable, ideally beyond 1.8.0.
5
What impact does CVE-2023-43667 have on Apache InLong?
CVE-2023-43667 can allow an attacker to create misleading log entries that can lead to further exploitation.