CVE-2023-31454

CVE-2023-31454: Apache InLong: IDOR make users can bind any cluster

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-732
Published May 22, 2023
Last update October 9, 2024

CVSS base score

What the vulnerability does

Description

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.  The attacker can bind any cluster, even if he is not the cluster owner. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it.[1] https://github.com/apache/inlong/pull/7947 https://github.com/apache/inlong/pull/7947

Key dates

Disclosure timeline

May 22, 2023 CVE published
October 9, 2024 Record updated