Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Streampark
APPApache< 2.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2025-54947CRITICAL9.8PL ✓same product
Apache StreamPark: zakodowany na stałe klucz szyfrowania (CVE-2025-54947)
CVE-2024-29070CRITICAL9.1PL ✓same product
Apache Streampark: sesja nie jest unieważniana po wylogowaniu
CVE-2022-46365CRITICAL9.1PL ✓same product
Apache StreamPark — nieautoryzowana modyfikacja kont użytkowników
CVE-2025-54981HIGH7.5same product
Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generat...
CVE-2025-30001HIGH7.3same product
Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache Stream...