Known vulnerabilities in Apache InLong 2.2.0

Software: Apache InLong
Version: 2.2.0
Software CPE: cpe:2.3:a:apache_foundation:apache_inlong:*:*:*:*:*:*:*:*
Total vulnerabilities: 9
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apache InLong version 2.2.0 Apache InLong 2.2.0 is affected by 9 vulnerabilities: 2 high, 2 medium, 5 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144850 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-63043
CWE-22 Medium
No
No
2.4.0 24.08.2026 SB20260824148
#VU144849 - Server-Side Request Forgery (SSRF)
CVE-2026-63044
CWE-918 Low
No
No
2.4.0 24.08.2026 SB20260824148
#VU144848 - Improper Access Control
CVE-2026-63042
CWE-284 Low
No
No
2.4.0 24.08.2026 SB20260824148
#VU144847 - Missing Authorization
CVE-2026-63040
CWE-862 Low
No
No
2.4.0 24.08.2026 SB20260824148
#VU144846 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-63039
CWE-89 High
No
No
2.4.0 24.08.2026 SB20260824148
#VU144845 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-63038
CWE-89 High
No
No
2.4.0 24.08.2026 SB20260824148
#VU144844 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-63037
CWE-89 Medium
No
No
2.4.0 24.08.2026 SB20260824148
#VU144843 - Improper Access Control
CVE-2026-63016
CWE-284 Low
No
No
2.4.0 24.08.2026 SB20260824148
#VU144842 - Improper Access Control
CVE-2026-63015
CWE-284 Low
No
No
2.4.0 24.08.2026 SB20260824148