CVE-2023-31453

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-31453
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-31453.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-31453
Aliases
Withdrawn
2024-05-08T06:52:41.057076Z
Published
2023-05-22T14:15:09Z
Modified
2023-11-01T05:02:00.833329Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the deleted subscription. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it.

[1]

https://github.com/apache/inlong/pull/7949 https://github.com/apache/inlong/pull/7949

References

Affected packages

Git / github.com/apache/inlong

Affected ranges

Type
GIT
Repo
https://github.com/apache/inlong
Events