CVE-2022-46365

CVSS v3.1 9.1 (Critical)
91% Progress
EPSS 0.16 % (53th)
0.16% Progress
Affected Products 1
Advisories 1

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow malicious attackers to send any username to modify and reset the account, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.

Weaknesses
CWE-20
Improper Input Validation
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2023-05-01 15:15:09
(16 months ago)
Updated Date
2023-05-09 18:04:19
(16 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Streampark from 1.0.0 version and prior 2.0.0 version cpe:2.3:a:apache:streampark >= 1.0.0 < 2.0.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...