First published: Mon May 22 2023(Updated: )
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it. [1] https://cveprocess.apache.org/cve5/[1]%C2%A0https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache InLong | >=1.4.0<=1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-31206.
The title of this vulnerability is 'Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.'
The Apache InLong software versions 1.4.0 through 1.6.0 are affected by this vulnerability.
The severity of CVE-2023-31206 is high with a CVSS score of 7.5.
To fix the CVE-2023-31206 vulnerability, users are advised to upgrade to Apache InLong version 1.7.0 or apply the applicable patches.