https://seclists.org/oss-sec/2025/q4/272: CVE-2025-54947: Apache StamPark: Use hard-coded key vulnerability
Published Dec 12, 2025
·Updated
Affected Software
1 affected component
Apache StreamPark<2.1.7
Frequently Asked Questions
1
What is the severity of CVE-2025-54947?
The severity of CVE-2025-54947 is categorized as important.
2
How do I fix CVE-2025-54947?
To fix CVE-2025-54947, upgrade Apache StreamPark to version 2.1.7 or later.
3
Which versions are affected by CVE-2025-54947?
CVE-2025-54947 affects Apache StreamPark versions 2.0.0 through 2.1.7.
4
What is the nature of the vulnerability in CVE-2025-54947?
The vulnerability in CVE-2025-54947 involves the use of a hard-coded encryption key.
5
When was CVE-2025-54947 published?
CVE-2025-54947 was published on December 12, 2025.