CVE-2022-45802
published 2023-05-01CVE-2022-45802: Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.31%
67.6th percentile
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | streampark | < 2.0.0 | 2.0.0 |
| apache_software_foundation | apache_streampark | >= 1.0.0 < 2.0.0 | 2.0.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache StreamPark Path Traversal vulnerability
ghsa·2023-07-06
CVE-2022-45802 [CRITICAL] CWE-22 Apache StreamPark Path Traversal vulnerability
Apache StreamPark Path Traversal vulnerability
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type. This means users may upload some high-risk files, and may upload them to any directory. Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.
OSV
Apache StreamPark Path Traversal vulnerability
osv·2023-07-06
CVE-2022-45802 [CRITICAL] Apache StreamPark Path Traversal vulnerability
Apache StreamPark Path Traversal vulnerability
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type. This means users may upload some high-risk files, and may upload them to any directory. Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-01
Published