First published: Mon May 22 2023(Updated: )
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 https://github.com/apache/inlong/pull/7836 to solve it.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache InLong | =1.5.0 | |
Apache InLong | =1.6.0 | |
maven/org.apache.inlong:manager-web | >=1.5.0<1.7.0 | 1.7.0 |
maven/org.apache.inlong:manager-service | >=1.5.0<1.7.0 | 1.7.0 |
maven/org.apache.inlong:manager-pojo | >=1.5.0<1.7.0 | 1.7.0 |
maven/org.apache.inlong:manager-dao | >=1.5.0<1.7.0 | 1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-31101.
The severity of CVE-2023-31101 is medium with a severity value of 6.5.
Apache InLong versions 1.5.0 and 1.6.0 are affected by CVE-2023-31101.
Users are advised to upgrade to Apache InLong's version 1.7.0 or later to fix the vulnerability.
You can find more information about CVE-2023-31101 at the following link: [https://lists.apache.org/thread/shvwwr6toqz5rr39rwh4k03z08sh9jmr](https://lists.apache.org/thread/shvwwr6toqz5rr39rwh4k03z08sh9jmr)