📦 Streampark

by Apache

🔍 What is Streampark?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-54947

CRITICAL CVSS 9.8 Dec 12, 2025

Apache StreamPark versions 2.0.0 through 2.1.6 use a hard-coded encryption key, allowing attackers to decrypt sensitive data or forge encrypted information through reverse engineering. This affects al...

CVE-2024-29070

CRITICAL CVSS 9.1 Jul 23, 2024

This vulnerability allows session tokens to remain valid after logout, enabling attackers to reuse stolen or previously obtained 'Authorization' tokens to access user data and perform unauthorized act...

CVE-2022-45802

CRITICAL CVSS 9.8 May 1, 2023

This vulnerability in Apache StreamPark allows any user to upload arbitrary JAR files without proper file type validation, potentially enabling remote code execution. Attackers could upload malicious ...

CVE-2025-54981

HIGH CVSS 7.5 Dec 12, 2025

This vulnerability in Apache StreamPark uses weak encryption (AES-ECB mode) and a weak random number generator for encrypting sensitive data like JWT tokens. Attackers could potentially decrypt authen...

CVE-2024-48988

HIGH CVSS 7.6 Aug 22, 2025

This CVE describes an SQL injection vulnerability in Apache StreamPark's SpringBoot distribution package that allows authenticated attackers to execute arbitrary SQL commands. It affects Apache Stream...

CVE-2024-29178

HIGH CVSS 8.8 Jul 18, 2024

This CVE describes a template injection vulnerability in Apache software versions before 2.1.4 that allows authenticated users to execute arbitrary code on the server. Attackers must first obtain vali...

CVE-2023-52290

HIGH CVSS 8.1 Jul 16, 2024

This SQL injection vulnerability in Apache StreamPark allows authenticated attackers to manipulate database queries through unvalidated sort parameters. It affects users of StreamPark console who can ...

CVE-2023-49898

HIGH CVSS 7.2 Dec 15, 2023

This vulnerability in Apache StreamPark allows authenticated users with system-level permissions to execute arbitrary commands through Maven compilation parameters. Attackers could achieve remote code...

CVE-2025-53960

MEDIUM CVSS 5.9 Dec 12, 2025

Apache StreamPark versions 2.0.0 through 2.1.6 use user passwords as JWT signing keys, allowing attackers who capture tokens to brute-force passwords offline or forge tokens if passwords are known. Th...

CVE-2024-34457

MEDIUM CVSS 6.5 Jul 22, 2024

This vulnerability in Apache Flink allows authenticated regular users to bypass authorization controls and access sensitive user information they shouldn't have permission to view. After successful lo...

CVE-2024-29120

MEDIUM CVSS 5.9 Jul 17, 2024

This vulnerability in Streampark versions before 2.1.4 allows authenticated users to access other users' sensitive information, including administrator credentials, by reusing the authentication token...

CVE-2024-29737

MEDIUM CVSS 4.7 Jul 17, 2024

This vulnerability in Apache StreamPark allows authenticated users with system-level permissions to execute arbitrary commands through improper input validation in the project module's build arguments...