CVE-2022-45802: Apache StreamPark (incubating): Upload any file to any directory
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
Other sources
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type. This means users may upload some high-risk files, and may upload them to any directory. Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45802?
The severity of CVE-2022-45802 is classified as high due to the potential for malicious file uploads.
How do I fix CVE-2022-45802?
To fix CVE-2022-45802, upgrade to Apache StreamPark version 2.0.0 or later.
What can happen if CVE-2022-45802 is exploited?
Exploitation of CVE-2022-45802 can lead to unauthorized execution of high-risk files on the server.
Which versions of StreamPark are affected by CVE-2022-45802?
Apache StreamPark versions prior to 2.0.0 are affected by CVE-2022-45802.
Is there a workaround for CVE-2022-45802?
There is no official workaround for CVE-2022-45802; upgrading is the recommended action.