https://seclists.org/oss-sec/2024/q3/70: CVE-2023-52290: Apache StamPark (incubating): Unchecked SQL query fields trigger SQL injection vulnerability
Published Jul 15, 2024
·Updated
Affected Software
1 affected component
Apache Streampark<2.1.4
Frequently Asked Questions
1
What is the severity of CVE-2023-52290?
The severity of CVE-2023-52290 is classified as low.
2
What versions of Apache StreamPark are affected by CVE-2023-52290?
CVE-2023-52290 affects Apache StreamPark (incubating) versions prior to 2.1.4.
3
What type of vulnerability is identified in CVE-2023-52290?
CVE-2023-52290 identifies an unchecked SQL query fields issue that triggers an SQL injection vulnerability.
4
How do I fix CVE-2023-52290?
To fix CVE-2023-52290, upgrade to Apache StreamPark version 2.1.4 or later.
5
Where in Apache StreamPark does CVE-2023-52290 occur?
CVE-2023-52290 occurs in the streampark-console application pages, specifically during the sorting by field feature.