CVE-2024-29120

CVSS V2 None CVSS V3 None
Description
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc.  Mitigation: all users should upgrade to 2.1.4
Overview
  • CVE ID
  • CVE-2024-29120
  • Assigner
  • apache
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-17T14:59:04.540Z
  • Last Modified Date
  • 2024-07-17T18:16:16.172Z
History
Created Old Value New Value Data Type Notes
2024-07-18 13:04:26 Added to TrackCVE