CVE-2023-34189: Apache InLong: General user can delete and update process
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.
Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109 to solve it.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-34189?
CVE-2023-34189 is a vulnerability that allows a general user in Apache InLong to delete and update processes that only the admin should be able to operate.
Which versions of Apache InLong are affected by CVE-2023-34189?
Apache InLong versions 1.4.0 through 1.7.0 are affected by CVE-2023-34189.
How can I fix the CVE-2023-34189 vulnerability?
To fix the CVE-2023-34189 vulnerability, you should upgrade Apache InLong to version 1.8.0 or above.
What is the severity of CVE-2023-34189?
CVE-2023-34189 has a severity rating of 6.5 (medium).
Where can I find more information about CVE-2023-34189?
More information about CVE-2023-34189 can be found at the following references: [https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s](https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s), [http://www.openwall.com/lists/oss-security/2023/07/25/2](http://www.openwall.com/lists/oss-security/2023/07/25/2), [https://nvd.nist.gov/vuln/detail/CVE-2023-34189](https://nvd.nist.gov/vuln/detail/CVE-2023-34189).