Products
Streampark
- < 2.1.4
Source
security@apache.org
Tags
CVE-2024-29120 details
Published : July 17, 2024, 3:15 p.m.
Last Modified : July 17, 2024, 4:15 p.m.
Last Modified : July 17, 2024, 4:15 p.m.
Description
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc. Mitigation: all users should upgrade to 2.1.4
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-212 | Improper Removal of Sensitive Information Before Storage or Transfer | The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors. |
References
URL | Source |
---|---|
http://www.openwall.com/lists/oss-security/2024/07/17/4 | security@apache.org |
https://lists.apache.org/thread/y3oqz7l8vd7jxxx3z2khgl625nvfr60j | security@apache.org |
This website uses the NVD API, but is not approved or certified by it.