Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS13eDc5LXIzcTgtZnE5aM4AA0cv
Apache InLong has Files or Directories Accessible to External Parties in Apache InLong
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7775 to solve it.
Permalink: https://github.com/advisories/GHSA-wx79-r3q8-fq9hJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13eDc5LXIzcTgtZnE5aM4AA0cv
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 1 year ago
Updated: about 1 year ago
CVSS Score: 9.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Percentage: 0.00328
EPSS Percentile: 0.70565
Identifiers: GHSA-wx79-r3q8-fq9h, CVE-2023-31066
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-31066
- https://lists.apache.org/thread/x7y05wo37sq5l9fnmmsjh2dr9kcjrcxf
- https://github.com/apache/inlong/pull/7775
- https://github.com/advisories/GHSA-wx79-r3q8-fq9h
Blast Radius: 14.1
Affected Packages
maven:org.apache.inlong:manager-web
Dependent packages: 1Dependent repositories: 35
Downloads:
Affected Version Ranges: >= 1.4.0, < 1.7.0
Fixed in: 1.7.0
All affected versions: 1.4.0, 1.5.0, 1.6.0
All unaffected versions: 1.3.0, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0, 1.12.0, 1.13.0, 2.0.0
maven:org.apache.inlong:manager-service
Dependent packages: 3Dependent repositories: 35
Downloads:
Affected Version Ranges: >= 1.4.0, < 1.7.0
Fixed in: 1.7.0
All affected versions: 1.4.0, 1.5.0, 1.6.0
All unaffected versions: 1.3.0, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0, 1.12.0, 1.13.0, 2.0.0