oss-sec mailing list archives

CVE-2023-34189: Apache InLong: General user can delete and update process


From: Charles Zhang <dockerzhang () apache org>
Date: Tue, 25 Jul 2023 02:27:32 +0000

Severity: important

Affected versions:

- Apache InLong 1.4.0 through 1.7.0

Description:

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects 
Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which 
only the admin can operate occurrences. 

Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick  https://github.com/apache/inlong/pull/8109  to 
solve it.

References:

https://inlong.apache.org
https://www.cve.org/CVERecord?id=CVE-2023-34189


Current thread: