Apache InLong: Insufficient Session Expiration in InLong
CVE-2023-31065
9.1CRITICAL
What is CVE-2023-31065?
The Insufficient Session Expiration vulnerability in Apache InLong allows attackers to exploit old sessions even after a user account is deleted or the password is changed. This can lead to unauthorized access and compromise user security. Users are encouraged to upgrade to version 1.7.0 or implement the required changes as noted in the pull requests provided by the Apache Software Foundation to mitigate this issue.
Affected Version(s)
Apache InLong 1.4.0 <= 1.6.0