CVE-2022-46365

CRITICAL

Apache StreamPark <2.0.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow malicious attackers to send any username to modify and reset the account, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.0027
EPSS Percentile 50.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
apache/streampark 1.0.0 - 2.0.0
org.apache.streampark/streampark 1.0.0 - 2.0.0Maven
Published May 01, 2023
Tracked Since Feb 18, 2026