A vulnerability has been identified in Apache InLong. The vulnerability could allow an attacker to perform Code Injection against InLong software. The vulnerability (CVE-2024- 36268) has a Critical CVSSv3.1 score of 9.8 out of 10.
CVE-2024-36268 is an Improper Control of Generation of Code ('Code Injection') vulnerability found in Apache InLong versions 1.10.0 through 1.12.0, which if exploited can lead to Remote Code Execution (RCE). This would allow an attacker to execute arbitrary code at will against a server as long as they have any adjacent network access to a vulnerable system. Due to InLong being an integration framework for massive amounts of data being used across multiple different industries the potential for data leakage and malicious exploitation are significant, and all businesses using the software should ensure they are not on a vulnerable version.
The issue affects customers with Apache InLong versions starting from 1.10.0 up to 1.12.0.