Описание
In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access.
This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.
Users are recommended to upgrade to version 2.1.7, which fixes the issue.
Ссылки
- Mailing List
- Mailing List
Уязвимые конфигурации
Конфигурация 1Версия от 2.0.0 (включая) до 2.1.7 (исключая)
cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.0004
Низкий
9.8 Critical
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-321
CWE-798
Связанные уязвимости
EPSS
Процентиль: 12%
0.0004
Низкий
9.8 Critical
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-321
CWE-798