CVE-2026-63038

🟠 Łataj w tym tygodniu

Wstrzyknięcie SQL w Apache InLong umożliwia atakującemu wykonanie dowolnego kodu SQL.

CVSS
9.8
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters.  This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/issues/12135 .

sql-injection Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-08-20 16:17:29 UTC
Ostatnia modyfikacja (NVD)2026-08-24 17:17:56 UTC
Referencje