Impact
Apache InLong exposes a server‑side request forgery flaw through the POST /api/node/testConnection endpoint. Any authenticated user, regardless of having an administrative role, can instruct the InLong Manager to open outbound HTTP or TCP connections to arbitrary internal hosts and ports. This breach exposes internal network resources to enumeration or potential exploitation and represents a CWE‑918 weakness in the input handling of the SSRF endpoint.
Affected Systems
The vulnerability affects Apache InLong versions from 2.0.0 up to, but not including, 2.4.0. The product is maintained by the Apache Software Foundation.
Risk and Exploitability
The CVSS score of 5.4 classifies this flaw as moderate, and the EPSS score of <1% indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog, so no known public exploits are documented. Nevertheless, authenticated users, regardless of role, can direct the InLong Manager to open outbound connections to arbitrary internal hosts, which can expose internal services and broaden the attack surface.
OpenCVE Enrichment