CVE-2024-34457: Apache StreamPark IDOR Vulnerability
Published Jul 22, 2024
·Updated
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config.
Mitigation:
all users should upgrade to 2.1.4
Affected Software
1 affected component
Apache Streampark<2.1.4
Event History
Jul 22, 2024
CVE Published
via MITRE·09:48 AM
Data Sourced
via MITRE·09:48 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34457?
CVE-2024-34457 is considered a critical vulnerability that allows unauthorized access to user information after login.
2
How do I fix CVE-2024-34457?
To fix CVE-2024-34457, all users should upgrade to Apache StreamPark version 2.1.4 or later.
3
Who is affected by CVE-2024-34457?
CVE-2024-34457 affects all users of Apache StreamPark versions prior to 2.1.4.
4
What kind of information can be accessed due to CVE-2024-34457?
Due to CVE-2024-34457, an attacker can access user flink information, including executeSQL and configuration data.
5
When was CVE-2024-34457 published?
CVE-2024-34457 was published in 2024 and affects specific versions of Apache StreamPark.