CVE-2024-29178: Apache StreamPark: FreeMarker SSTI RCE Vulnerability
On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability.
Mitigation:
all users should upgrade to 2.1.4
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29178?
CVE-2024-29178 is considered a moderate-impact vulnerability due to its requirement for user login to exploit.
How do I fix CVE-2024-29178?
To mitigate CVE-2024-29178, upgrade to version 2.1.4 or later of Apache StreamPark.
What type of attack does CVE-2024-29178 enable?
CVE-2024-29178 allows for a template injection attack that can lead to Remote Code Execution.
Who is affected by CVE-2024-29178?
All users of Apache StreamPark versions prior to 2.1.4 are affected by CVE-2024-29178.
What conditions must be met for an attack using CVE-2024-29178 to succeed?
The attacker must be able to successfully log into the system to exploit CVE-2024-29178.