CVE-2023-31454: Apache InLong: IDOR make users can bind any cluster
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.
The attacker can bind any cluster, even if he is not the cluster owner. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it.[1]
https://github.com/apache/inlong/pull/7947 https://github.com/apache/inlong/pull/7947
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-31454?
CVE-2023-31454 is a vulnerability in Apache InLong, an open-source project developed by the Apache Software Foundation.
How does CVE-2023-31454 affect Apache InLong?
CVE-2023-31454 allows an attacker to bind any cluster in Apache InLong, even if they are not the cluster owner.
What is the severity of CVE-2023-31454?
CVE-2023-31454 has a severity rating of high, with a CVSS score of 7.5 out of 10.
How can I fix the CVE-2023-31454 vulnerability?
To fix the CVE-2023-31454 vulnerability, users are advised to upgrade to Apache InLong version 1.7.0 or later.
Where can I find more information about CVE-2023-31454?
More information about CVE-2023-31454 can be found in the Apache Software Foundation mailing list: [https://lists.apache.org/thread/nqt1tr6pbq8q4b033d7sg5gltx5pmjgl](https://lists.apache.org/thread/nqt1tr6pbq8q4b033d7sg5gltx5pmjgl)