CVE-2024-29178

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
18/07/2024
Last modified:
13/02/2025

Description

On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability.<br /> <br /> Mitigation:<br /> <br /> all users should upgrade to 2.1.4

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:* 2.1.4 (excluding)