CVE-2023-43668
- EPSS 0.05%
- Veröffentlicht 16.10.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:35
Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, some sensitive params checks will be bypassed, like "autoDeserizalize","allowLoadLocalInfile".... . Use...
CVE-2023-43667
- EPSS 0.91%
- Veröffentlicht 16.10.2023 09:15:10
- Zuletzt bearbeitet 16.06.2025 17:15:26
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, mak...
CVE-2023-43666
- EPSS 0.45%
- Veröffentlicht 16.10.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:34
Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0...
CVE-2023-34189
- EPSS 0.11%
- Veröffentlicht 25.07.2023 08:15:10
- Zuletzt bearbeitet 13.02.2025 17:16:34
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can...
CVE-2023-35088
- EPSS 0.51%
- Veröffentlicht 25.07.2023 08:15:10
- Zuletzt bearbeitet 13.02.2025 17:16:39
Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. In the toAuditCkSql method, the groupId, strea...
CVE-2023-34434
- EPSS 0.39%
- Veröffentlicht 25.07.2023 08:15:10
- Zuletzt bearbeitet 13.02.2025 17:16:36
Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could bypass the current logic and achieve arbitrary file reading. To solve it, use...
CVE-2023-31103
- EPSS 0.15%
- Veröffentlicht 22.05.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:01:25
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of cluster of InLong. Users are advised to up...
CVE-2023-31101
- EPSS 0.14%
- Veröffentlicht 22.05.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:01:25
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advi...
CVE-2023-31098
- EPSS 0.17%
- Veröffentlicht 22.05.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:01:24
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character or symbol), attackers can eas...
CVE-2023-31066
- EPSS 0.23%
- Veröffentlicht 22.05.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:01:20
Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! U...