CVE-2023-31066 – Apache InLong: Insecure direct object references for inlong sources
https://notcve.org/view.php?id=CVE-2023-31066
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7775 https://github.com/apache/inlong/pull/7775 to solve it. • https://lists.apache.org/thread/x7y05wo37sq5l9fnmmsjh2dr9kcjrcxf • CWE-552: Files or Directories Accessible to External Parties •
CVE-2023-31098 – Apache InLong: Weak Password Implementation in InLong
https://notcve.org/view.php?id=CVE-2023-31098
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's password and access the account. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7805 https://github.com/apache/inlong/pull/7805 to solve it. • https://lists.apache.org/thread/1fvloc3no1gbffzrcsx9ltsg08wr2d1w • CWE-521: Weak Password Requirements •
CVE-2023-31103 – Apache InLong: Attackers can change the immutable name and type of cluster
https://notcve.org/view.php?id=CVE-2023-31103
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891 to solve it. • https://lists.apache.org/thread/bv51zhjookcnfbz8b0xsl9wv78sn0j1p • CWE-668: Exposure of Resource to Wrong Sphere •
CVE-2023-31206 – Apache InLong: Attackers can change the immutable name and type of nodes
https://notcve.org/view.php?id=CVE-2023-31206
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it. [1] https://cveprocess.apache.org/cve5/[1]%C2%A0https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891 • https://lists.apache.org/thread/qb7zffo785wzpmsobjqcypodngw6kg6x • CWE-668: Exposure of Resource to Wrong Sphere •
CVE-2023-31453 – Apache InLong: IDOR make users can delete others' subscription
https://notcve.org/view.php?id=CVE-2023-31453
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the deleted subscription. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/7949 https://github.com/apache/inlong/pull/7949 • https://lists.apache.org/thread/9nz8o2skgc5230w276h4w92j0zstnl06 • CWE-732: Incorrect Permission Assignment for Critical Resource •