Apache InLong has Weak Password Requirements in Apache InLong
Critical severity
GitHub Reviewed
Published
Jul 6, 2023
to the GitHub Advisory Database
•
Updated Nov 10, 2023
Package
Affected versions
>= 1.1.0, < 1.7.0
Patched versions
1.47.0
Description
Published by the National Vulnerability Database
May 22, 2023
Published to the GitHub Advisory Database
Jul 6, 2023
Reviewed
Jul 6, 2023
Last updated
Nov 10, 2023
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's password and access the account. Users are advised to upgrade to Apache InLong 1.7.0 or cherry-pick apache/inlong#7805 to solve it.
References