https://seclists.org/oss-sec/2024/q3/97: CVE-2024-34457: Apache StamPark IDOR Vulnerability
Published Jul 22, 2024
·Updated
Affected Software
1 affected component
Apache Streampark<2.1.4
Frequently Asked Questions
1
What is the severity of CVE-2024-34457?
The severity of CVE-2024-34457 is classified as moderate.
2
Which versions of Apache StreamPark are affected by CVE-2024-34457?
Apache StreamPark versions from 1.0.0 before 2.1.4 are affected by CVE-2024-34457.
3
How do I fix CVE-2024-34457?
To fix CVE-2024-34457, upgrade Apache StreamPark to version 2.1.4 or later.
4
What does CVE-2024-34457 exploit?
CVE-2024-34457 exploits an Insecure Direct Object Reference (IDOR) vulnerability that allows unauthorized access to user flink information.
5
What kind of data is exposed in CVE-2024-34457?
CVE-2024-34457 exposes sensitive information such as executeSQL and configuration details of other users.