CVE-2023-34189

MEDIUM

Apache InLong <1.7.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.  Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (2)
apache/inlong 1.4.0 - 1.7.0
org.apache.inlong/inlong-manager 1.4.0 - 1.8.0Maven
Published Jul 25, 2023
Tracked Since Feb 18, 2026