Apache InLong: Insecure direct object references for inlong sources
CVE-2023-31066

9.1CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
22 May 2023

Summary

A vulnerability has been identified in Apache InLong that enables different users to inadvertently interact with and manipulate the sources of others. Specifically, users operating on versions ranging from 1.4.0 to 1.6.0 can delete, edit, stop, or start the data sources belonging to other users. This lack of proper access controls raises significant security concerns regarding user data integrity and system stability. To mitigate this issue, users are urged to upgrade to version 1.7.0 or apply the necessary fixes as detailed in the provided GitHub pull request.

Affected Version(s)

Apache InLong 1.4.0 <= 1.6.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lujie.ac.cn
.