Apache StreamPark
cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*
- >= 2.0.0, < 2.1.7
A vulnerability exists in Apache StreamPark versions 2.0.0 prior to 2.1.7, due to the use of the AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens. This may have exposed sensitive authentication data.
The vulnerability could lead to the exposure of sensitive authentication data by allowing encrypted information to be decrypted or manipulated, undermining the integrity and confidentiality of the data.
Users are advised to upgrade to Apache StreamPark version 2.1.7, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.