Skip to main content

Vendor/product archive

apache / streampark CVEs

Beta · best-effort

17 CVEs tagged to apache / streampark4 Critical, 6 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-53960

Published Dec 12, 2025

When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An attacker can exploit this vuln…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54981

Published Dec 12, 2025

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risk…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54947

Published Dec 12, 2025

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-30001

Published Oct 10, 2025

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to v…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48988

Published Aug 22, 2025

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes t…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29070

Published Jul 23, 2024

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authenticatio…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-34457

Published Jul 22, 2024

On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, incl…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29178

Published Jul 18, 2024

On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29120

Published Jul 17, 2024

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use thi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29737

Published Jul 17, 2024

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote comma…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52291

Published Jul 17, 2024

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote comma…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52290

Published Jul 16, 2024

In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is genera…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49898

Published Dec 15, 2023

In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30867

Published Dec 15, 2023

In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syn…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46365

Published May 1, 2023

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified wh…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-45802

Published May 1, 2023

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-45801

Published May 1, 2023

Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on us…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1