Apache

Streampipes

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Published 03.03.2025 11:15:11
  • Last modified 08.07.2025 14:02:27

Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 ...

  • EPSS 1.33%
  • Published 17.07.2024 10:15:01
  • Last modified 21.11.2024 09:13:28

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and auth...

  • EPSS 1.05%
  • Published 17.07.2024 09:15:02
  • Last modified 21.11.2024 09:11:59

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with the same email address until the email address is r...

  • EPSS 0.71%
  • Published 17.07.2024 09:15:02
  • Last modified 21.11.2024 09:14:16

Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom endpoints from which to install additional pipeline elements. These en...

  • EPSS 79.22%
  • Published 24.06.2024 10:15:09
  • Last modified 15.07.2025 15:39:09

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to ta...

  • EPSS 0.1%
  • Published 23.06.2023 08:15:09
  • Last modified 21.11.2024 08:01:55

A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is r...