CVE-2023-31469

CVSS V2 None CVSS V3 None
Description
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by upgrading to StreamPipes 0.92.0.
Overview
  • CVE ID
  • CVE-2023-31469
  • Assigner
  • apache
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-06-23T07:07:42.875Z
  • Last Modified Date
  • 2023-06-23T07:07:42.875Z
References
Reference URL Reference Tags
https://lists.apache.org/thread/c4y8kf9bzpf36v4bottfmd8tc9cxo19m vendor-advisory
History
Created Old Value New Value Data Type Notes
2024-06-24 21:38:28 Added to TrackCVE