CVE-2023-31064

CVE-2023-31064: Apache InLong: Insecurity direct object references cancelling applications

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-552 · Files accessible externally
Published May 22, 2023
Last update October 9, 2024

CVSS base score

What the vulnerability does

Description

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application that doesn't belongs to it. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7799 https://github.com/apache/inlong/pull/7799 to solve it.

Key dates

Disclosure timeline

May 22, 2023 CVE published
October 9, 2024 Record updated