CVE-2023-31066

CVE-2023-31066: Apache InLong: Insecure direct object references for inlong sources

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-552 · Files accessible externally
Published May 22, 2023
Last update October 9, 2024

CVSS base score

What the vulnerability does

Description

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7775 https://github.com/apache/inlong/pull/7775 to solve it.

Key dates

Disclosure timeline

May 22, 2023 CVE published
October 9, 2024 Record updated