Apache

Streampark

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 17.07.2024 09:15:02
  • Zuletzt bearbeitet 13.02.2025 18:15:54

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user...

  • EPSS 0.33%
  • Veröffentlicht 16.07.2024 08:15:02
  • Zuletzt bearbeitet 10.07.2025 18:18:52

In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is generated using this field. However, because this sort field isn't validated,...

  • EPSS 1.9%
  • Veröffentlicht 15.12.2023 13:15:07
  • Zuletzt bearbeitet 21.11.2024 08:33:59

In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisite for a suc...

  • EPSS 0.4%
  • Veröffentlicht 15.12.2023 13:15:07
  • Zuletzt bearbeitet 21.11.2024 08:01:00

In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the j...

  • EPSS 0.04%
  • Veröffentlicht 01.05.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 07:30:28

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user i...

  • EPSS 0.07%
  • Veröffentlicht 01.05.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:29:44

Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it...

  • EPSS 0.07%
  • Veröffentlicht 01.05.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:29:44

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should up...