7.5
CVE-2026-63043
- EPSS -
- Veröffentlicht 20.08.2026 15:53:11
- Zuletzt bearbeitet 27.08.2026 00:02:30
- Erkennungen
Apache InLong: Agent path traversal via unvalidated file source path
Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12146 .
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-23 Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
https://lists.apache.org/thread/0ohn861tzd9g7nsosd6oz3of6dvhvqnk
http://www.openwall.com/lists/oss-security/2026/08/20/16