CVE-2023-31064: Apache InLong has Files or Directories Accessible to External Parties
7.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.41098%
CWE
Published
7/6/2023
Updated
11/10/2023
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.inlong:manager-workflow | maven | >= 1.2.0, < 1.7.0 | 1.7.0 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from missing authorization checks in workflow cancellation operations. The patch (PR #7799) explicitly adds user authentication to workflow operations, indicating these functions previously handled cancellation requests without verifying user ownership. The CWE-552 classification suggests exposed endpoints allowed unauthorized access to privileged operations, consistent with unauthenticated workflow cancellation endpoints in the manager-workflow component.