CVE-2024-48988

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/08/2025
Last modified:
04/11/2025

Description

SQL Injection vulnerability in Apache StreamPark.<br /> <br /> This issue affects Apache StreamPark: from 2.1.4 before 2.1.6.<br /> <br /> Users are recommended to upgrade to version 2.1.6, which fixes the issue.<br /> <br /> <br /> This vulnerability is present only in the distribution package (SpringBoot platform) and does not involve Maven artifacts.<br /> It can only be exploited after a user has successfully logged into the platform (implying that the attacker would first need to compromise the login authentication). <br /> As a result, the associated risk is considered relatively low.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:* 2.1.4 (including) 2.1.6 (excluding)