GHSA-h79m-5cm2-278c
GitHub Security Advisory
User data exposure in Apache InLong
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0. Users registered in InLong who joined later can see deleted users' data. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7836 to solve it.
Affected Packages
Maven
org.apache.inlong:manager-dao
Affected versions:
1.5.0
(fixed in 1.7.0)
Maven
org.apache.inlong:manager-pojo
Affected versions:
1.5.0
(fixed in 1.7.0)
Maven
org.apache.inlong:manager-service
Affected versions:
1.5.0
(fixed in 1.7.0)
Maven
org.apache.inlong:manager-web
Affected versions:
1.5.0
(fixed in 1.7.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 31, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.