CVE-2025-54981: Apache StreamPark: Weak Encryption Algorithm in StreamPark
Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data
This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.
Users are recommended to upgrade to version 2.1.7, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54981?
CVE-2025-54981 is considered a high severity vulnerability due to the use of weak encryption algorithms.
How do I fix CVE-2025-54981?
To fix CVE-2025-54981, upgrade Apache StreamPark to version 2.1.7 or later.
What vulnerabilities does CVE-2025-54981 introduce?
CVE-2025-54981 introduces the risk of exposing sensitive authentication data due to weak encryption methods.
What versions of Apache StreamPark are affected by CVE-2025-54981?
CVE-2025-54981 affects Apache StreamPark versions from 2.0.0 to before 2.1.7.
What encryption algorithm is vulnerable in CVE-2025-54981?
CVE-2025-54981 is vulnerable due to the use of the AES cipher in ECB mode.