[MAVEN:GHSA-7MHC-76HF-3JP9] Apache InLong Exposure of Resource to Wrong Sphere vulnerability

Severity High
Affected Packages 5
Fixed Packages 5
CVEs 1

Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7891 to solve it.

ID
MAVEN:GHSA-7MHC-76HF-3JP9
Severity
high
URL
https://github.com/advisories/GHSA-7mhc-76hf-3jp9
Published
2023-07-06T21:14:59
(14 months ago)
Modified
2023-11-10T05:02:27
(10 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.inlong/manager-web org.apache.inlong manager-web >= 1.4.0 < 1.7.0
Fixed pkg:maven/org.apache.inlong/manager-web org.apache.inlong manager-web = 1.7.0
Affected pkg:maven/org.apache.inlong/manager-test org.apache.inlong manager-test >= 1.4.0 < 1.7.0
Fixed pkg:maven/org.apache.inlong/manager-test org.apache.inlong manager-test = 1.7.0
Affected pkg:maven/org.apache.inlong/manager-service org.apache.inlong manager-service >= 1.4.0 < 1.7.0
Fixed pkg:maven/org.apache.inlong/manager-service org.apache.inlong manager-service = 1.7.0
Affected pkg:maven/org.apache.inlong/manager-pojo org.apache.inlong manager-pojo >= 1.4.0 < 1.7.0
Fixed pkg:maven/org.apache.inlong/manager-pojo org.apache.inlong manager-pojo = 1.7.0
Affected pkg:maven/org.apache.inlong/manager-dao org.apache.inlong manager-dao >= 1.4.0 < 1.7.0
Fixed pkg:maven/org.apache.inlong/manager-dao org.apache.inlong manager-dao = 1.7.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...