PT-2023-2846 · Apache · Apache Inlong

Published

2023-05-22

·

Updated

2024-10-11

·

CVE-2023-31453

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache InLong versions 1.2.0 through 1.6.0
Description The issue is related to incorrect permission assignment for critical resources in Apache InLong, allowing a remote attacker to impact the integrity and availability of protected information. Specifically, the attacker can delete others' subscriptions, even if they are not the owner of the deleted subscription.
Recommendations For Apache InLong versions 1.2.0 through 1.6.0, upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7949 to solve the issue. As a temporary workaround, consider restricting access to subscription management features to minimize the risk of exploitation.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2023-02791
CVE-2023-31453
GHSA-8RJH-3MHM-966Q

Affected Products

Apache Inlong