Critical severity9.1NVD Advisory· Published May 22, 2023· Updated Jun 17, 2026
CVE-2023-31066
CVE-2023-31066
Description
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7775 https://github.com/apache/inlong/pull/7775 to solve it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.inlong:manager-serviceMaven | >= 1.4.0, < 1.7.0 | 1.7.0 |
org.apache.inlong:manager-webMaven | >= 1.4.0, < 1.7.0 | 1.7.0 |
Affected products
4- ghsa-coords2 versions
>= 1.4.0, < 1.7.0+ 1 more
- (no CPE)range: >= 1.4.0, < 1.7.0
- (no CPE)range: >= 1.4.0, < 1.7.0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-wx79-r3q8-fq9hghsaADVISORY
- lists.apache.org/thread/x7y05wo37sq5l9fnmmsjh2dr9kcjrcxfnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-31066ghsaADVISORY
- github.com/apache/inlong/pull/7775ghsaWEB
News mentions
0No linked articles in our index yet.