CVE-2023-31101: Apache InLong: Users who joined later can see the data of deleted users
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 https://github.com/apache/inlong/pull/7836 to solve it.
Other sources
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 to solve it.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Insecure Default Initialization of Resource Vulnerability in Apache InLong?
The vulnerability ID is CVE-2023-31101.
What is the severity of CVE-2023-31101?
The severity of CVE-2023-31101 is medium with a severity value of 6.5.
Which version of Apache InLong is affected by CVE-2023-31101?
Apache InLong versions 1.5.0 and 1.6.0 are affected by CVE-2023-31101.
How can I fix the Insecure Default Initialization of Resource Vulnerability in Apache InLong?
Users are advised to upgrade to Apache InLong's version 1.7.0 or later to fix the vulnerability.
Where can I find more information about CVE-2023-31101?
You can find more information about CVE-2023-31101 at the following link: [https://lists.apache.org/thread/shvwwr6toqz5rr39rwh4k03z08sh9jmr](https://lists.apache.org/thread/shvwwr6toqz5rr39rwh4k03z08sh9jmr)