CVE-2026-63046
🟡 Monitoruj
Wstrzyknięcie poleceń w Apache InLong umożliwia wykonanie dowolnych poleceń powłoki.
CVSS
8.8
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1]/[2] to solve it. [1] https://github.com/apache/inlong/pull/12151 . [2] https://github.com/apache/inlong/pull/12155 .
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-08-21 09:16:40 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-21 19:17:31 UTC |
Referencje
- https://lists.apache.org/thread/2pgz70rz9ozfm7vm5c33po3yyspq846y (security@apache.org)