HIGH🇵🇱 Wersja polska

CVE-2025-30001

CVSS 7.3v3.1pub. 2025-10-10upd. 2025-11-04

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • Apache Streampark

    APP
    Apache
    2.1.4 – 2.1.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-54947CRITICAL9.8PL ✓same product

Apache StreamPark: zakodowany na stałe klucz szyfrowania (CVE-2025-54947)

CVE-2024-29070CRITICAL9.1PL ✓same product

Apache Streampark: sesja nie jest unieważniana po wylogowaniu

CVE-2022-46365CRITICAL9.1PL ✓same product

Apache StreamPark — nieautoryzowana modyfikacja kont użytkowników

CVE-2022-45802CRITICAL9.8PL ✓same product

Apache Streampark — nieograniczony upload plików JAR umożliwia RCE

CVE-2025-54981HIGH7.5same product

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generat...