Impact
The vulnerability is an improper neutralization of special elements used in an SQL command in Apache InLong’s AuditAlertRuleService. Unvalidated MyBatis dollar‑sign interpolation allows an attacker to inject arbitrary SQL statements, potentially exposing or modifying sensitive data. This flaw is a classic SQL injection (CWE‑89) and can lead to confidentiality and integrity violations.
Affected Systems
Apache InLong versions from 2.0.0 up to but not including 2.4.0 are vulnerable. Both the 2.2.x and 2.3.x series fall within this range.
Risk and Exploitability
The issue is not listed in the CISA Known Exploited Vulnerabilities catalog and no EPSS score is available, so the exact exploitation probability is unknown. However, because the vulnerability can be exploited through the exposed service interface, it is likely remotely exploitable. Given the severity of SQL injection, the risk is considered high until a patch is applied.
OpenCVE Enrichment