https://seclists.org/oss-sec/2023/q4/111: CVE-2023-43666: Apache InLong: General user Unauthorized access User Management
Published Oct 16, 2023
·Updated
Affected Software
1 affected component
Apache Inlong>=1.4.0<=1.8.0
Frequently Asked Questions
1
What is the severity of CVE-2023-43666?
CVE-2023-43666 has been rated as important.
2
Which versions of Apache InLong are affected by CVE-2023-43666?
Apache InLong versions 1.4.0 through 1.8.0 are affected by CVE-2023-43666.
3
What type of vulnerability is CVE-2023-43666?
CVE-2023-43666 is an Insufficient Verification of Data Authenticity vulnerability.
4
What is the impact of exploiting CVE-2023-43666?
Exploitation of CVE-2023-43666 allows general users to view all user data, including Admin account details.
5
How do I fix CVE-2023-43666?
To remediate CVE-2023-43666, it is advised to update to a version of Apache InLong that is not affected by this vulnerability.