CVE-2023-34189

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.  Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.
References
Link Resource
http://www.openwall.com/lists/oss-security/2023/07/25/2 Mailing List Third Party Advisory
https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s Mailing List Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*

History

02 Aug 2023, 18:51

Type Values Removed Values Added
CPE cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*
First Time Apache
Apache inlong
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s - (MISC) https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s - Mailing List, Vendor Advisory
References (MISC) http://www.openwall.com/lists/oss-security/2023/07/25/2 - (MISC) http://www.openwall.com/lists/oss-security/2023/07/25/2 - Mailing List, Third Party Advisory

25 Jul 2023, 13:00

Type Values Removed Values Added
References
  • (MISC) http://www.openwall.com/lists/oss-security/2023/07/25/2 -

25 Jul 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-25 08:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-34189

Mitre link : CVE-2023-34189

CVE.ORG link : CVE-2023-34189


JSON object : View

Products Affected

apache

  • inlong
CWE
CWE-668

Exposure of Resource to Wrong Sphere