CVE Database
/

CVE-2022-45802

Back to search

CVE-2022-45802

Published: May 1, 2023

Modified: Oct 21, 2024

PUBLISHED

Description

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later

VendorProductVersions

Apache Software Foundation

Apache StreamPark (incubating)

affected
1.0.0 - < 2.0.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now