First published: Mon May 01 2023(Updated: )
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache StreamPark | <2.0.0 | |
maven/org.apache.streampark:streampark-common_2.11 | <2.0.0 | 2.0.0 |
maven/org.apache.streampark:streampark-common_2.12 | <2.0.0 | 2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.