Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS13eDc5LXIzcTgtZnE5aM4AA0cv

Apache InLong has Files or Directories Accessible to External Parties in Apache InLong

Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7775 to solve it.

Permalink: https://github.com/advisories/GHSA-wx79-r3q8-fq9h
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13eDc5LXIzcTgtZnE5aM4AA0cv
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: 10 months ago
Updated: 6 months ago


CVSS Score: 9.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Identifiers: GHSA-wx79-r3q8-fq9h, CVE-2023-31066
References: Repository: https://github.com/apache/inlong
Blast Radius: 14.1

Affected Packages

maven:org.apache.inlong:manager-web
Dependent packages: 1
Dependent repositories: 35
Downloads:
Affected Version Ranges: >= 1.4.0, < 1.7.0
Fixed in: 1.7.0
All affected versions: 1.4.0, 1.5.0, 1.6.0
All unaffected versions: 1.3.0, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0
maven:org.apache.inlong:manager-service
Dependent packages: 3
Dependent repositories: 35
Downloads:
Affected Version Ranges: >= 1.4.0, < 1.7.0
Fixed in: 1.7.0
All affected versions: 1.4.0, 1.5.0, 1.6.0
All unaffected versions: 1.3.0, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0