CVE-2022-45802

CVSS V2 None CVSS V3 None
Description
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
Overview
  • CVE ID
  • CVE-2022-45802
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-05-01T15:15:08
  • Last Modified Date
  • 2023-05-01T15:15:08
History
Created Old Value New Value Data Type Notes
2023-05-01 16:00:59 Added to TrackCVE
2023-05-01 16:01:01 Weakness Enumeration new