First published: Mon Mar 03 2025(Updated: )
Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache StreamPipes | <=0.95.1 | |
maven/org.apache.streampipes:streampipes-parent | <0.97.0 | 0.97.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24778 is considered a high severity vulnerability due to improper privilege management allowing unauthorized access to resources.
To fix CVE-2024-24778, upgrade Apache StreamPipes to version 0.97.0 or later.
CVE-2024-24778 impacts users of Apache StreamPipes versions up to and including 0.95.1.
CVE-2024-24778 is classified as an improper privilege management vulnerability in a REST interface.
Yes, registered users can exploit CVE-2024-24778 to access unauthorized resources if they know the resource ID.