CVE-2023-31206 – org.apache.inlong:manager-pojo
Package
Manager: maven
Name: org.apache.inlong:manager-pojo
Vulnerable Version: >=1.4.0 <1.7.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00145 pctl0.35446
Details
Apache InLong Exposure of Resource to Wrong Sphere vulnerability Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7891 to solve it.
Metadata
Created: 2023-07-06T21:14:59Z
Modified: 2023-07-06T23:40:45Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-f475-jgg3-3jwc/GHSA-f475-jgg3-3jwc.json
CWE IDs: ["CWE-668"]
Alternative ID: GHSA-f475-jgg3-3jwc
Finding: F017
Auto approve: 1