Insufficient Session Expiration in Apache InLong - CVE-2023-31065
Published: August 1, 2023
Apache InLong
Apache Foundation
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient session expiration issue. A remote non-authenticated attacker can obtain or guess session token and gain unauthorized access to session that belongs to another user. This includes sessions for accounts that have been deleted or the password has been changed.