GHSA-rf76-whgp-fp56
GitHub Security Advisory
Apache InLong vulnerable to Incorrect Permission Assignment for Critical Resource
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong from 1.2.0 through 1.6.0. The attacker can bind any cluster, even if he is not the cluster owner. Users are advised to upgrade to Apache InLong 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7947 to solve it.
Affected Packages
Maven
org.apache.inlong:manager-service
Affected versions:
1.2.0
(fixed in 1.7.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.