VendorsApachestreamparkall versions
Vulnerabilities

Apache Software Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2022-45802
Apache StreamPark (incubating): Upload any file to any directory
Published 2023-05-01 · Modified
9.8EPSS 0.013
CVE-2025-54947
Apache StreamPark: Use hard-coded key vulnerability
Published 2025-12-12 · Analyzed
9.8EPSS 0.005
CVE-2022-46365
Apache StreamPark (incubating): Logic error causing any account reset
Published 2023-05-01 · Modified
9.1EPSS 0.015
CVE-2024-29070
Apache StreamPark: session not invalidated after logout
Published 2024-07-23 · Analyzed
9.1EPSS 0.008
CVE-2023-52291
Apache StreamPark (incubating): Unchecked maven build params could trigger remote command execution
Published 2024-07-17 · Modified
8.8EPSS 0.016
CVE-2024-29178
Apache StreamPark: FreeMarker SSTI RCE Vulnerability
Published 2024-07-18 · Modified
8.8EPSS 0.012
CVE-2024-29737
Apache StreamPark (incubating): maven build params could trigger remote command execution
Published 2024-07-17 · Modified
8.8EPSS 0.011
CVE-2023-52290
Apache StreamPark (incubating): Unchecked SQL query fields trigger SQL injection vulnerability
Published 2024-07-16 · Analyzed
8.1EPSS 0.006
CVE-2024-48988
Apache StreamPark: SQL injection vulnerability
Published 2025-08-22 · Modified
7.6EPSS 0.006
CVE-2025-54981
Apache StreamPark: Weak Encryption Algorithm in StreamPark
Published 2025-12-12 · Analyzed
7.5EPSS 0.002
CVE-2025-30001
Apache StreamPark: Authenticated users can trigger remote command execution
Published 2025-10-10 · Modified
7.3EPSS 0.006
CVE-2023-49898
Apache StreamPark (incubating): Authenticated system users could trigger remote command execution
Published 2023-12-15 · Modified
7.2EPSS 0.023
CVE-2024-34457
Apache StreamPark IDOR Vulnerability
Published 2024-07-22 · Modified
6.5EPSS 0.007
CVE-2024-29120
Apache StreamPark: Information leakage vulnerability
Published 2024-07-17 · Analyzed
5.9EPSS 0.003
CVE-2025-53960
Apache StreamPark: Uses the user’s password as the secret key
Published 2025-12-12 · Analyzed
5.9EPSS 0.003
CVE-2022-45801
Apache StreamPark (incubating): LDAP Injection Vulnerability
Published 2023-05-01 · Modified
5.4EPSS 0.011
CVE-2023-30867
Apache StreamPark (incubating): Authenticated system users could trigger SQL injection vulnerability
Published 2023-12-15 · Modified
4.9EPSS 0.009