[oss-security] CVE-2025-30001: Apache StreamPark: Authenticated users can trigger remote command execution

2025-09-06 Thread Huajie Wang
Severity: low Affected versions: - Apache StreamPark 2.1.4 before 2.1.6 Description: Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the

[oss-security] CVE-2024-48988: Apache StreamPark: SQL injection vulnerability

2025-08-22 Thread Huajie Wang
Severity: low Affected versions: - Apache StreamPark 2.1.4 before 2.1.6 Description: SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability

[oss-security] CVE-2024-29070: Apache StreamPark: session not invalidated after logout

2024-07-22 Thread Huajie Wang
Severity: moderate Affected versions: - Apache StreamPark 1.0.0 before 2.1.4 Description: On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authoriza

[oss-security] CVE-2024-34457: Apache StreamPark IDOR Vulnerability

2024-07-22 Thread Huajie Wang
Severity: moderate Affected versions: - Apache StreamPark 1.0.0 before 2.1.4 Description: On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and con

[oss-security] CVE-2024-29178: Apache StreamPark: FreeMarker SSTI RCE Vulnerability

2024-07-18 Thread Huajie Wang
Severity: moderate Affected versions: - Apache StreamPark 1.0.0 before 2.1.4 Description: On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an att

[oss-security] CVE-2024-29120: Apache StreamPark: Information leakage vulnerability

2024-07-17 Thread Huajie Wang
Severity: important Affected versions: - Apache StreamPark 2.0.0 before 2.1.4 Description: In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request

[oss-security] CVE-2024-29737: Apache StreamPark (incubating): maven build params could trigger remote command execution

2024-07-17 Thread Huajie Wang
Severity: low Affected versions: - Apache StreamPark (incubating) 2.0.0 before 2.1.4 Description: In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, Th

[oss-security] CVE-2023-52291: Apache StreamPark (incubating): Unchecked maven build params could trigger remote command execution

2024-07-17 Thread Huajie Wang
Severity: low Affected versions: - Apache StreamPark (incubating) 2.0.0 before 2.1.4 Description: In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, Th

[oss-security] CVE-2023-52290: Apache StreamPark (incubating): Unchecked SQL query fields trigger SQL injection vulnerability

2024-07-15 Thread Huajie Wang
Severity: low Affected versions: - Apache StreamPark (incubating) 2.0.0 before 2.1.4 Description: In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is generated using this f