High severity7.5NVD Advisory· Published May 22, 2023· Updated Jun 17, 2026
CVE-2023-31064
CVE-2023-31064
Description
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. the user in InLong could cancel an application that doesn't belongs to it. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7799 https://github.com/apache/inlong/pull/7799 to solve it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.inlong:manager-workflowMaven | >= 1.2.0, < 1.7.0 | 1.7.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-3p9p-59qf-mqwhghsaADVISORY
- lists.apache.org/thread/1osd2k3t3qol2wdsswqtr9gxdkf78n00nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-31064ghsaADVISORY
- github.com/apache/inlong/pull/7799ghsaWEB
News mentions
0No linked articles in our index yet.