logo

CVE-2022-45801 org.apache.streampark:streampark

Package

Manager: maven
Name: org.apache.streampark:streampark
Vulnerable Version: >=1.0.0 <2.0.0

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00065 pctl0.20456

Details

Apache StreamPark LDAP Injection vulnerability Apache StreamPark versions 1.0.0 to 2.0.0 have an LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's possible to modify LDAP statements through techniques similar to SQL Injection. LDAP injection attacks could result in the granting of permissions to unauthorized queries, and content modification inside the LDAP tree. This risk may only occur when the user logs in with ldap, and the user name and password login will not be affected, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.

Metadata

Created: 2023-05-01T15:30:26Z
Modified: 2023-05-09T18:49:23Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-pjfj-qvqw-3f6v/GHSA-pjfj-qvqw-3f6v.json
CWE IDs: ["CWE-74"]
Alternative ID: GHSA-pjfj-qvqw-3f6v
Finding: F184
Auto approve: 1