CVE-2023-31453

HIGH

Apache InLong <1.7.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the deleted subscription. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/7949 https://github.com/apache/inlong/pull/7949

References (1)

Core 1
Core References
Mailing List, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/9nz8o2skgc5230w276h4w92j0zstnl06

Scores

CVSS v3 7.5
EPSS 0.0022
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (3)
apache/inlong 1.2.0 - 1.6.0
org.apache.inlong/manager-service 1.2.0 - 1.7.0Maven
org.apache.inlong/manager-web 1.2.0 - 1.7.0Maven
Published May 22, 2023
Tracked Since Feb 18, 2026