In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc. Mitigation: all users should upgrade to 2.1.4
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Link | Tags |
---|---|
https://lists.apache.org/thread/y3oqz7l8vd7jxxx3z2khgl625nvfr60j | vendor advisory mailing list |
http://www.openwall.com/lists/oss-security/2024/07/17/4 | mailing list |