CVE-2024-29120

July 17, 2024, 4:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Streampark

  • < 2.1.4

Source

security@apache.org

Tags

CVE-2024-29120 details

Published : July 17, 2024, 3:15 p.m.
Last Modified : July 17, 2024, 4:15 p.m.

Description

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc.  Mitigation: all users should upgrade to 2.1.4

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
This website uses the NVD API, but is not approved or certified by it.