CyberRota Analysis
AI-GeneratedApache InLong versions prior to 2.4.0 are vulnerable due to a lack of authorization checks in the StreamSource component, allowing any authenticated user to logically delete all stream sources. This could lead to significant data loss and disruption of services for organizations relying on this functionality. Users of affected versions should prioritize upgrading to 2.4.0 or apply the recommended patch to mitigate this risk.
Original NVD Description
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12145 .
Related CVEs
Other vulnerabilities affecting the same vendor(s)