Executive brief
Apache InLong is a data integration platform used to collect, transform, and deliver data across systems. A SQL injection vulnerability in its audit alert rule service allows attackers to inject malicious SQL commands, potentially enabling unauthorized access to sensitive data stored in the database or disruption of the data integration service.
Technical details
The vulnerability is a SQL injection (CWE-89) in the AuditAlertRuleService component, arising from improper neutralization of special elements in SQL commands via unvalidated MyBatis dollar-sign string interpolation. An attacker can inject arbitrary SQL by manipulating input values that are concatenated directly into SQL statements without proper parameterization or sanitization. The attack is network-accessible and does not require authentication or user interaction beyond crafting a malicious request. An attacker can execute arbitrary SQL queries with the database credentials of the application, potentially exfiltrating data, modifying records, or causing denial of service. The fix is available in Apache InLong version 2.4.0 or via a specific cherry-pick commit.
Affected products
- Apache InLong from 2.0.0 before 2.4.0
Timeline
- 2026-08-20: disclosed
- 2026-08-20: patched: Fixed in Apache InLong 2.4.0