Impact
The vulnerability is a relative path traversal flaw that allows an attacker to read any file on the Agent host filesystem. By specifying a malicious file source path, the attacker can access privileged configuration files, credentials, or other sensitive data. The impact is a confidentiality breach; no known denial‑of‑service or code‑execution vectors are documented in the CVE data.
Affected Systems
Affected versions are all Apache InLong releases from 2.0.0 up to, but not including, 2.4.0. The products impacted are the Apache InLong Agent components distributed by the Apache Software Foundation. No specific sub‑components or third‑party libraries are noted as affected.
Risk and Exploitability
The CVSS score is not provided, but the path traversal flaw is generally considered high severity due to the potential for arbitrary file disclosure. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, indicating no confirmed public exploits yet. The likely attack vector is remote, provided an attacker can supply a crafted file source path to the Agent (e.g., via exposed API or configuration upload). Based on the description, it is inferred that authentication or authorization controls are insufficient to prevent path manipulation.
OpenCVE Enrichment