Vulnerability Description
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the deleted subscription. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/7949 https://github.com/apache/inlong/pull/7949
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Inlong | >= 1.2.0, <= 1.6.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/9nz8o2skgc5230w276h4w92j0zstnl06Mailing ListVendor Advisory
- https://lists.apache.org/thread/9nz8o2skgc5230w276h4w92j0zstnl06Mailing ListVendor Advisory
FAQ
What is CVE-2023-31453?
CVE-2023-31453 is a vulnerability with a CVSS score of 7.5 (HIGH). Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete othe...
How severe is CVE-2023-31453?
CVE-2023-31453 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31453?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Inlong.