https://seclists.org/oss-sec/2023/q4/113: CVE-2023-43668: Apache InLong: Jdbc Connection Security Bypass in InLong
Published Oct 16, 2023
·Updated
Affected Software
1 affected component
Apache Inlong>=1.4.0<=1.8.0
Frequently Asked Questions
1
What is the severity of CVE-2023-43668?
The severity of CVE-2023-43668 is classified as important.
2
What versions of Apache InLong are affected by CVE-2023-43668?
CVE-2023-43668 affects Apache InLong versions 1.4.0 through 1.8.0.
3
What type of vulnerability is CVE-2023-43668?
CVE-2023-43668 is an authorization bypass vulnerability due to user-controlled key issues.
4
How do I fix CVE-2023-43668?
To mitigate CVE-2023-43668, upgrade to a version of Apache InLong that is later than 1.8.0.
5
What specific checks are bypassed in CVE-2023-43668?
CVE-2023-43668 allows bypassing checks on sensitive parameters like 'autoDeserialize'.