Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-31065


Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  An old session can be used by an attacker even after the user has been deleted or the password has been changed. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 https://github.com/apache/inlong/pull/7836 , https://github.com/apache/inlong/pull/7884 https://github.com/apache/inlong/pull/7884 to solve it.


Published

2023-05-22T16:15:10.027

Last Modified

2024-11-21T08:01:20.653

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-613

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache inlong ≤ 1.6.0 Yes

References