-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing authorization checks when binding clusters. The fix in PR #7947 explicitly adds user authentication to the cluster tag binding process. Since the vulnerability title references 'bind any cluster' and the patch modifies ClusterTagController, we can infer the bindClusterTag method (or equivalent) lacked ownership validation in vulnerable versions. The file path follows standard Java package structure for Spring controllers in Apache InLong's manager-service component.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.inlong:manager-service | maven | >= 1.2.0, < 1.7.0 | 1.7.0 |
Ongoing coverage of React2Shell