https://seclists.org/oss-sec/2023/q4/280: CVE-2023-30867: Apache StreamPark (incubating): Authenticated system users could trigger SQL injection vulnerability
Published Dec 15, 2023
·Updated
Affected Software
1 affected component
Apache Streampark<2.1.2
Frequently Asked Questions
1
What is the severity of CVE-2023-30867?
The severity of CVE-2023-30867 is low.
2
What are the affected versions for CVE-2023-30867?
The affected versions for CVE-2023-30867 are Apache StreamPark (incubating) 2.0.0 before 2.1.2.
3
How do I fix CVE-2023-30867?
To fix CVE-2023-30867, upgrade to Apache StreamPark version 2.1.2 or later.
4
What type of vulnerability is CVE-2023-30867?
CVE-2023-30867 is an SQL injection vulnerability.
5
How can authenticated users exploit CVE-2023-30867?
Authenticated system users could exploit CVE-2023-30867 through certain features that involve a name-based fuzzy search.