Impact
Apache InLong exposes a server‑side request forgery flaw through the POST /api/node/testConnection endpoint. Any authenticated user, regardless of having an administrative role, can instruct the InLong Manager to open outbound HTTP or TCP connections to arbitrary internal hosts and ports. This breach exposes internal network resources to enumeration or potential exploitation and represents a CWE‑918 weakness in the input handling of the SSRF endpoint.
Affected Systems
The vulnerability affects Apache InLong versions from 2.0.0 up to, but not including, 2.4.0. The product is maintained by the Apache Software Foundation.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits yet. However, because the flaw allows authenticated users to reach arbitrary internal addresses, the risk can become significant if sensitive internal services are reachable. The lack of administrative privilege requirement lowers the authentication barrier, increasing the potential attack surface.
OpenCVE Enrichment