Описание
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.
Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109 to solve it.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.4.0 (включая) до 1.7.0 (включая)
cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00107
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-668
Связанные уязвимости
CVSS3: 6.5
github
больше 2 лет назад
Apache InLong: General user can delete and update process
EPSS
Процентиль: 29%
0.00107
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-668