CVE-2024-36268

CVE-2024-36268: Apache InLong TubeMQ Client: Remote Code Execution vulnerability

Vendor Apache Software Foundation
Product Apache InLong TubeMQ Client
Weakness CWE-94 · Code injection
Published August 2, 2024
Last update August 22, 2024

CVSS base score

What the vulnerability does

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/10251

Key dates

Disclosure timeline

August 2, 2024 CVE published
August 22, 2024 Record updated