Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcf8-5j78-887v

Опубликовано: 17 июл. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Apache StreamPark: Information leakage vulnerability

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc. 

Mitigation:

all users should upgrade to 2.1.4

Пакеты

Наименование

org.apache.streampark:streampark

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.1.4

2.1.4

EPSS

Процентиль: 24%
0.0008
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-212
CWE-922

Связанные уязвимости

CVSS3: 5.9
nvd
больше 1 года назад

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc.  Mitigation: all users should upgrade to 2.1.4

EPSS

Процентиль: 24%
0.0008
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-212
CWE-922