Impact
Apache InLong's Agent Installer has an Argument Injection flaw (CWE‑88) that allows an attacker to run arbitrary shell commands when the installer executes the ExecuteLinux.exeCmd() function without filtering input. Because the installer uses default credentials, an unauthenticated or low‑privilege user can trigger remote command execution. This flaw can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Vendors impacted are the Apache Software Foundation, specifically the Apache InLong monitoring platform. Versions from 2.0.0 up through but not including 2.4.0 contain the vulnerable logic in the Agent Installer module. The default credentials use default values that are widely known, creating a clear path for exploitation.
Risk and Exploitability
The vulnerability has a high severity with a CVSS base score of 8.8; the EPSS score is < 1% and the entry is not listed in KEV. Attackers can exploit the flaw remotely by interacting with the Agent Installer service from a host with the default credentials or by exploiting misconfiguration. Because the flaw permits arbitrary command execution, the risk is severe for any system lacking additional controls, and immediate patching is advised.
OpenCVE Enrichment