MEDIUM🇵🇱 Wersja polska

CVE-2025-53960

CVSS 5.9v3.1pub. 2025-12-12upd. 2025-12-16

When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An attacker can exploit this vulnerability to perform offline brute-force attacks on the user's password using a captured JWT, or to arbitrarily forge identity tokens for the user if the password is already known, ultimately leading to complete account takeover. This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Apache Streampark

    APP
    Apache
    2.0.0 – 2.1.7 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-54947CRITICAL9.8PL ✓same product

Apache StreamPark: zakodowany na stałe klucz szyfrowania (CVE-2025-54947)

CVE-2024-29070CRITICAL9.1PL ✓same product

Apache Streampark: sesja nie jest unieważniana po wylogowaniu

CVE-2022-46365CRITICAL9.1PL ✓same product

Apache StreamPark — nieautoryzowana modyfikacja kont użytkowników

CVE-2022-45802CRITICAL9.8PL ✓same product

Apache Streampark — nieograniczony upload plików JAR umożliwia RCE

CVE-2025-54981HIGH7.5same product

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generat...