Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6874-289g-f7h7

Опубликовано: 06 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Apache StreamPark Path Traversal vulnerability

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type. This means users may upload some high-risk files, and may upload them to any directory. Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.

Пакеты

Наименование

org.apache.streampark:streampark-common_2.12

maven
Затронутые версииВерсия исправления

< 2.0.0

2.0.0

Наименование

org.apache.streampark:streampark-common_2.11

maven
Затронутые версииВерсия исправления

< 2.0.0

2.0.0

EPSS

Процентиль: 27%
0.00097
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later

EPSS

Процентиль: 27%
0.00097
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434