CVE-2023-31469
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
23/06/2023
Last modified:
09/10/2024
Description
<br />
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles.<br />
The issue is resolved by upgrading to StreamPipes 0.92.0.<br />
<br />
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:streampipes:*:*:*:*:*:*:*:* | 0.69.0 (including) | 0.91.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



