GHSA-f475-jgg3-3jwc
Dashboard / Vulnerabilities / GHSA-f475-jgg3-3jwc
Summary: Apache InLong Exposure of Resource to Wrong Sphere vulnerability
Details: Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7891 to solve it.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-31206, https://github.com/apache/inlong/pull/7891, https://github.com/apache/inlong, https://lists.apache.org/thread/qb7zffo785wzpmsobjqcypodngw6kg6x
Affected packages
Package
Name: org.apache.inlong:manager-pojo
Purl: pkg:maven/org.apache.inlong/manager-pojo
Affected ranges
Type: ECOSYSTEM
Events:
