Lucene search

K
osvGoogleOSV:CVE-2023-31454
HistoryMay 22, 2023 - 2:15 p.m.

CVE-2023-31454

2023-05-2214:15:09
Google
osv.dev
6
cve-2023-31454
apache inlong
critical resource vulnerability

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

61.1%

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.

The attacker can bind any cluster, even if he is not the cluster owner. Users are advised to upgrade to Apache InLong’s 1.7.0 or cherry-pick [1] to solve it.[1]

https://github.com/apache/inlong/pull/7947 https://github.com/apache/inlong/pull/7947

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

61.1%

Related for OSV:CVE-2023-31454