Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.
Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109 to solve it.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2023/07/25/2 | Mailing List Third Party Advisory |
https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s | Mailing List Vendor Advisory |
Configurations
History
02 Aug 2023, 18:51
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | (MISC) https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s - Mailing List, Vendor Advisory | |
References | (MISC) http://www.openwall.com/lists/oss-security/2023/07/25/2 - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:* |
25 Jul 2023, 13:00
Type | Values Removed | Values Added |
---|---|---|
References |
|
25 Jul 2023, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-25 08:15
Updated : 2024-02-05 00:01
NVD link : CVE-2023-34189
Mitre link : CVE-2023-34189
CVE.ORG link : CVE-2023-34189
JSON object : View
Products Affected
apache
- inlong
CWE
CWE-668
Exposure of Resource to Wrong Sphere