CVE-2023-31065Insufficient Session Expiration in Software Foundation Apache Inlong

Severity
9.1CRITICALNVD
EPSS
0.3%
top 49.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22
Latest updateJul 6

Description

Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. An old session can be used by an attacker even after the user has been deleted or the password has been changed. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 https://github.com/apache/inlong/pull/7836 , https://github.com/apache/inlong/pull/7884 https://github.com/apache/inlong/

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

CVEListV5apache_software_foundation/apache_inlong1.4.01.6.0
NVDapache/inlong1.4.01.6.0

🔴Vulnerability Details

3
OSV
Apache InLong Insufficient Session Expiration vulnerability2023-07-06
GHSA
Apache InLong Insufficient Session Expiration vulnerability2023-07-06
CVEList
Apache InLong: Insufficient Session Expiration in InLong2023-05-22
CVE-2023-31065 — Insufficient Session Expiration | cvebase