CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-29120: Apache StreamPark: Information leakage vulnerability

Description

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc. 

Mitigation:

all users should upgrade to 2.1.4

Classification

CVE ID: CVE-2024-29120

Affected Products

Vendor: Apache Software Foundation

Product: Apache StreamPark

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.98% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://lists.apache.org/thread/y3oqz7l8vd7jxxx3z2khgl625nvfr60j
http://www.openwall.com/lists/oss-security/2024/07/17/4

Timeline