PT-2023-23156 · Apache · Apache Inlong

Lujie.Ac.Cn

·

Published

2023-05-22

·

Updated

2023-05-27

·

CVE-2023-31101

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache InLong versions 1.5.0 through 1.6.0
Description This issue allows users registered in InLong who joined later to see deleted users' data. The problem is related to insecure default initialization of resources.
Recommendations For Apache InLong versions 1.5.0 through 1.6.0, upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 to solve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-31101
GHSA-H79M-5CM2-278C

Affected Products

Apache Inlong