Miggo Logo

CVE-2023-31064: Apache InLong has Files or Directories Accessible to External Parties

7.5

CVSS Score
3.1

Basic Information

EPSS Score
0.41098%
Published
7/6/2023
Updated
11/10/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.apache.inlong:manager-workflowmaven>= 1.2.0, < 1.7.01.7.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability stems from missing authorization checks in workflow cancellation operations. The patch (PR #7799) explicitly adds user authentication to workflow operations, indicating these functions previously handled cancellation requests without verifying user ownership. The CWE-552 classification suggests exposed endpoints allowed unauthorized access to privileged operations, consistent with unauthenticated workflow cancellation endpoints in the manager-workflow component.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

*il*s or *ir**tori*s ****ssi*l* to *xt*rn*l P*rti*s vuln*r**ility in *p**** So*tw*r* *oun**tion *p**** InLon*. T*is issu* *****ts *p**** InLon* *rom *.*.* t*rou** *.*.*.T** us*r in InLon* *oul* **n**l *n *ppli**tion t**t *o*sn't **lon* to it. Us*rs *

Reasoning

T** vuln*r**ility st*ms *rom missin* *ut*oriz*tion ****ks in work*low **n**ll*tion op*r*tions. T** p*t** (PR #****) *xpli*itly ***s us*r *ut**nti**tion to work*low op*r*tions, in*i**tin* t**s* *un*tions pr*viously **n*l** **n**ll*tion r*qu*sts wit*ou
CVE-2023-31064: InLong Application Auth Bypass | Miggo