logo

CVE-2023-31206 org.apache.inlong:manager-web

Package

Manager: maven
Name: org.apache.inlong:manager-web
Vulnerable Version: >=1.4.0 <1.7.0

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00145 pctl0.35446

Details

Apache InLong Exposure of Resource to Wrong Sphere vulnerability Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7891 to solve it.

Metadata

Created: 2023-07-06T21:14:59Z
Modified: 2023-07-06T23:40:45Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-f475-jgg3-3jwc/GHSA-f475-jgg3-3jwc.json
CWE IDs: ["CWE-668"]
Alternative ID: GHSA-f475-jgg3-3jwc
Finding: F017
Auto approve: 1