cbcvebase.
CVE-2023-52291
published 2024-07-17

CVE-2023-52291: In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert…

PriorityP429medium4.7CVSS 3.1
AVNACLPRHUINSUCLILAL
EPSS
1.61%
73.2th percentile
In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low. Background: In the "Project" module, the maven build args “<” operator causes command injection. e.g : “< (curl http://xxx.com )” will be executed as a command injection, Mitigation: all users should upgrade to 2.1.4, The "<" operator will blocked。

Affected

2 ranges
VendorProductVersion rangeFixed in
apachestreampark>= 2.0.0 < 2.1.42.1.4
apache_software_foundationapache_streampark>= 2.0.0 < 2.1.42.1.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.