CVE-2024-34457

On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:*

History

11 Sep 2024, 11:15

Type Values Removed Values Added
References
  • {'url': 'http://www.openwall.com/lists/oss-security/2024/07/22/2', 'name': 'http://www.openwall.com/lists/oss-security/2024/07/22/2', 'tags': ['Mailing List'], 'refsource': ''}
  • () https://www.openwall.com/lists/oss-security/2024/07/22/2 -
Summary On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4

10 Sep 2024, 15:09

Type Values Removed Values Added
First Time Apache streampark
Apache
CPE cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-269 CWE-639
References () https://lists.apache.org/thread/brlfrmvw9dcv38zoofmhxg7qookmwn7j - () https://lists.apache.org/thread/brlfrmvw9dcv38zoofmhxg7qookmwn7j - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2024/07/22/2 - () http://www.openwall.com/lists/oss-security/2024/07/22/2 - Mailing List

22 Jul 2024, 14:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/07/22/2 -

22 Jul 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 10:15

Updated : 2024-11-04 22:35


NVD link : CVE-2024-34457

Mitre link : CVE-2024-34457


JSON object : View

Products Affected

apache

  • streampark
CWE
CWE-639

Authorization Bypass Through User-Controlled Key