Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5h8-2pjw-vg3j

Опубликовано: 06 июл. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Apache StreamPark Improper Input Validation vulnerability

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow malicious attackers to send any username to modify and reset the account, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.

Пакеты

Наименование

org.apache.streampark:streampark

maven
Затронутые версииВерсия исправления

>= 1.0.0, < 2.0.0

2.0.0

EPSS

Процентиль: 19%
0.0006
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.1
nvd
почти 3 года назад

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow malicious attackers to send any username to modify and reset the account, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.

EPSS

Процентиль: 19%
0.0006
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20