Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40693
HistoryMay 26, 2023 - 3:54 a.m.

Privilege Escalation

2023-05-2603:54:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
vulnerability
org.apache.inlong
privilege escalation
permission
attacker
http request
software

EPSS

0.04

Percentile

92.1%

org.apache.inlong is vulnerable to Privilege Escalation. The vulnerability exists because the library does not properly remove the permission when deleting a user, allowing an attacker with a valid (but unprivileged) account to send malicious login requests and follow it with a subsequent HTTP request using the returned cookie.

EPSS

0.04

Percentile

92.1%

Related for VERACODE:40693