Apache InLong: Attackers can change the immutable name and type of nodes
CVE-2023-31206
7.5HIGH
Summary
The vulnerability in Apache InLong allows attackers to change the immutable name and type of nodes, potentially leading to unauthorized access to resources. Users running Apache InLong versions from 1.4.0 to 1.6.0 are advised to upgrade to version 1.7.0 or apply specific patches to mitigate this issue.
Affected Version(s)
Apache InLong 1.4.0 <= 1.6.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved