Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1mNDc1LWpnZzMtM2p3Y84AA0cl
Apache InLong Exposure of Resource to Wrong Sphere vulnerability
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7891 to solve it.
Permalink: https://github.com/advisories/GHSA-f475-jgg3-3jwcJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mNDc1LWpnZzMtM2p3Y84AA0cl
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 1 year ago
Updated: about 1 year ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Identifiers: GHSA-f475-jgg3-3jwc, CVE-2023-31206
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-31206
- https://lists.apache.org/thread/qb7zffo785wzpmsobjqcypodngw6kg6x
- https://github.com/apache/inlong/pull/7891
- https://github.com/advisories/GHSA-f475-jgg3-3jwc
Blast Radius: 11.6
Affected Packages
maven:org.apache.inlong:manager-web
Dependent packages: 1Dependent repositories: 35
Downloads:
Affected Version Ranges: >= 1.4.0, < 1.7.0
Fixed in: 1.7.0
All affected versions: 1.4.0, 1.5.0, 1.6.0
All unaffected versions: 1.3.0, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0, 1.12.0, 1.13.0, 2.0.0
maven:org.apache.inlong:manager-test
Dependent packages: 3Dependent repositories: 35
Downloads:
Affected Version Ranges: >= 1.4.0, < 1.7.0
Fixed in: 1.7.0
All affected versions: 1.4.0, 1.5.0, 1.6.0
All unaffected versions: 1.3.0, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0, 1.12.0, 1.13.0, 2.0.0
maven:org.apache.inlong:manager-service
Dependent packages: 3Dependent repositories: 35
Downloads:
Affected Version Ranges: >= 1.4.0, < 1.7.0
Fixed in: 1.7.0
All affected versions: 1.4.0, 1.5.0, 1.6.0
All unaffected versions: 1.3.0, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0, 1.12.0, 1.13.0, 2.0.0
maven:org.apache.inlong:manager-dao
Dependent packages: 2Dependent repositories: 35
Downloads:
Affected Version Ranges: >= 1.4.0, < 1.7.0
Fixed in: 1.7.0
All affected versions: 1.4.0, 1.5.0, 1.6.0
All unaffected versions: 1.3.0, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0, 1.12.0, 1.13.0, 2.0.0
maven:org.apache.inlong:manager-pojo
Dependent packages: 3Dependent repositories: 30
Downloads:
Affected Version Ranges: >= 1.4.0, < 1.7.0
Fixed in: 1.7.0
All affected versions: 1.4.0, 1.5.0, 1.6.0
All unaffected versions: 1.3.0, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0, 1.12.0, 1.13.0, 2.0.0