CVE-2023-43667

CVE-2023-43667: Apache InLong: Log Injection in Global functions

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-74
Published October 16, 2023
Last update June 16, 2025

CVSS base score

What the vulnerability does

Description

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it harder to audit and trace malicious activities. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/8628

Key dates

Disclosure timeline

October 16, 2023 CVE published
June 16, 2025 Record updated