CVE-2023-34189
Apache InLong: General user can delete and update process
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
25 Jul 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.
Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109 to solve it.
Affected products
Apache Software Foundation · Apache InLongWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →