VYPR

Maven package

org.apache.inlong/manager-web

pkg:maven/org.apache.inlong/manager-web

Vulnerabilities (7)

  • CVE-2023-31062May 22, 2023
    affected >= 1.2.0, < 1.7.0fixed 1.7.0

    Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.  When the attacker has access to a valid (but unprivileged) account, the exploit can be executed using Burp Suite by sending a log

  • CVE-2023-31065May 22, 2023
    affected >= 1.4.0, < 1.7.0fixed 1.7.0

    Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  An old session can be used by an attacker even after the user has been deleted or the password has been changed. Users are ad

  • CVE-2023-31066May 22, 2023
    affected >= 1.4.0, < 1.7.0fixed 1.7.0

    Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade to

  • CVE-2023-31101May 22, 2023
    affected >= 1.5.0, < 1.7.0fixed 1.7.0

    Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advised to upgrade to Apache InLon

  • CVE-2023-31103May 22, 2023
    affected >= 1.4.0, < 1.7.0fixed 1.7.0

    Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  Attackers can change the immutable name and type of cluster of InLong. Users are advised to upgrade to Apache InLong's 1.7.0

  • CVE-2023-31206May 22, 2023
    affected >= 1.4.0, < 1.7.0fixed 1.7.0

    Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or

  • CVE-2023-31453May 22, 2023
    affected >= 1.2.0, < 1.7.0fixed 1.7.0

    Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can delete others' subscriptions, even if they are not the owner of the deleted subscription. U