Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3q63-2qmj-vfp6

Опубликовано: 20 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1]  https://github.com/apache/inlong/pull/12145 .

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1]  https://github.com/apache/inlong/pull/12145 .

EPSS

Процентиль: 29%
0.00365
Низкий

8.1 High

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 8.1
nvd
9 дней назад

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12145 .

EPSS

Процентиль: 29%
0.00365
Низкий

8.1 High

CVSS3

Дефекты

CWE-552