Lucene search

K
cvelistApacheCVELIST:CVE-2023-31454
HistoryMay 22, 2023 - 1:23 p.m.

CVE-2023-31454 Apache InLong: IDOR make users can bind any cluster

2023-05-2213:23:17
CWE-732
apache
www.cve.org
4
apache inlong
idor
cluster binding

EPSS

0.002

Percentile

61.1%

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.

The attacker can bind any cluster, even if he is not the cluster owner. Users are advised to upgrade to Apache InLong’s 1.7.0 or cherry-pick [1] to solve it.[1]

https://github.com/apache/inlong/pull/7947 https://github.com/apache/inlong/pull/7947

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache InLong",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "1.6.0",
        "status": "affected",
        "version": "1.2.0",
        "versionType": "semver"
      }
    ]
  }
]

EPSS

0.002

Percentile

61.1%

Related for CVELIST:CVE-2023-31454