CVE-2024-34457

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/07/2024
Last modified:
04/11/2024

Description

On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone&amp;#39;s user flink information, including executeSQL and config.<br /> <br /> Mitigation:<br /> <br /> all users should upgrade to 2.1.4

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:* 2.1.4 (excluding)