|
Message-ID: <5023d80a-778c-9a04-a62e-6514055d7e7e@apache.org> Date: Mon, 22 Jul 2024 09:33:34 +0000 From: Huajie Wang <benjobs@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2024-34457: Apache StreamPark IDOR Vulnerability Severity: moderate Affected versions: - Apache StreamPark 1.0.0 before 2.1.4 Description: On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 Credit: L0ne1y (reporter) References: https://streampark.incubator.apache.org https://www.cve.org/CVERecord?id=CVE-2024-34457
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.