CVE-2023-34189

MEDIUM

Apache InLong <1.7.0 - Privilege Escalation

Title source: llm

Description

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.  Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.

Scores

CVSS v3 6.5
EPSS 0.0011
EPSS Percentile 28.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-668
Status published

Affected Products (2)

apache/inlong < 1.7.0
org.apache.inlong/inlong-manager < 1.8.0Maven

Timeline

Published Jul 25, 2023
Tracked Since Feb 18, 2026