First published: Tue Jul 25 2023(Updated: )
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences. Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109 to solve it.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.inlong:inlong-manager | >=1.4.0<1.8.0 | 1.8.0 |
Apache InLong | >=1.4.0<=1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34189 is a vulnerability that allows a general user in Apache InLong to delete and update processes that only the admin should be able to operate.
Apache InLong versions 1.4.0 through 1.7.0 are affected by CVE-2023-34189.
To fix the CVE-2023-34189 vulnerability, you should upgrade Apache InLong to version 1.8.0 or above.
CVE-2023-34189 has a severity rating of 6.5 (medium).
More information about CVE-2023-34189 can be found at the following references: [https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s](https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s), [http://www.openwall.com/lists/oss-security/2023/07/25/2](http://www.openwall.com/lists/oss-security/2023/07/25/2), [https://nvd.nist.gov/vuln/detail/CVE-2023-34189](https://nvd.nist.gov/vuln/detail/CVE-2023-34189).