CVE-2023-43666

CVE-2023-43666: Apache InLong: General user Unauthorized access User Management

Vendor Apache Software Foundation
Product Apache InLong
Weakness CWE-345
Published October 16, 2023
Last update September 16, 2024

CVSS base score

What the vulnerability does

Description

Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/8623

Key dates

Disclosure timeline

October 16, 2023 CVE published
September 16, 2024 Record updated