PT-2023-5725 · Apache · Apache Inlong

Charles Zhang

+1

·

Publicado

2023-05-22

·

Atualizado

2024-10-11

·

CVE-2023-31098

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache InLong versions 1.1.0 through 1.6.0
Description The issue is related to weak password requirements in Apache InLong. When users change their password to a simple password, attackers can easily guess the user's password and access the account. This allows a remote attacker to gain access to a user's account.
Recommendations To solve the issue, users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7805. As a temporary workaround, consider implementing strong password policies to minimize the risk of exploitation. Restrict access to accounts with simple passwords to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06395
CVE-2023-31098
GHSA-W3WR-GMWF-R333

Produtos afetados

Apache Inlong