CVE-2023-31098
CVSS V2 None
CVSS V3 None
Description
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.
When users change their password to a simple password (with any character or
symbol), attackers can easily guess the user's password and access the account.
Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick https://github.com/apache/inlong/pull/7805 https://github.com/apache/inlong/pull/7805 to solve it.
Overview
- CVE ID
- CVE-2023-31098
- Assigner
- security@apache.org
- Vulnerability Status
- Awaiting Analysis
- Published Version
- 2023-05-22T16:15:10
- Last Modified Date
- 2023-05-22T16:15:51
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://lists.apache.org/thread/1fvloc3no1gbffzrcsx9ltsg08wr2d1w |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-31098 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-31098 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-05-22 17:01:11 | Added to TrackCVE | |||
2023-05-22 17:01:16 | Weakness Enumeration | new |