Impact
This vulnerability stems from missing authorization checks on the DataNode management endpoints within Apache InLong. As a result, any authenticated user with access to the manager has the ability to create, modify, and delete Data Node definitions. The weakness is a failure to enforce proper access control (CWE‑552), which allows an attacker to alter routing or storage configurations, potentially exposing or tampering with data flows.
Affected Systems
Affected vendors and products include the Apache Software Foundation's Apache InLong system. Versions from 2.0.0 up to, but not including, 2.4.0 are vulnerable. No specific minor version numbers are listed, so all releases in that range should be considered at risk.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is credential‑based and limited to users who can authenticate to the manager. The CVSS score is 8.1 and the EPSS score is < 1%, indicating a high severity but a low current likelihood of exploitation. In environments where the manager interface is exposed to untrusted networks or where privileged accounts are widely distributed, the potential impact is significant. Since the vulnerability is not listed in CISA's KEV catalog, no public exploits are known at this time, but the missing authorization could be leveraged for internal privilege escalation or unintended data handling, warranting immediate attention.
OpenCVE Enrichment