CVE-2023-34189

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.  Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*

History

13 Feb 2025, 17:16

Type Values Removed Values Added
Summary Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.  Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it. Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.  Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.
CWE CWE-668
References (MISC) https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s - Mailing List, Vendor Advisory () https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s - Mailing List, Vendor Advisory
References (MISC) http://www.openwall.com/lists/oss-security/2023/07/25/2 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2023/07/25/2 - Mailing List, Third Party Advisory

02 Aug 2023, 18:51

Type Values Removed Values Added
First Time Apache inlong
Apache
References (MISC) https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s - (MISC) https://lists.apache.org/thread/smxqyx43hxjvzv4w71n2n3rfho9p378s - Mailing List, Vendor Advisory
References (MISC) http://www.openwall.com/lists/oss-security/2023/07/25/2 - (MISC) http://www.openwall.com/lists/oss-security/2023/07/25/2 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

25 Jul 2023, 13:00

Type Values Removed Values Added
References
  • (MISC) http://www.openwall.com/lists/oss-security/2023/07/25/2 -

25 Jul 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-25 08:15

Updated : 2025-02-13 17:16


NVD link : CVE-2023-34189

Mitre link : CVE-2023-34189


JSON object : View

Products Affected

apache

  • inlong
CWE

No CWE.