Description
On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even after logout.
Mitigation:
all users should upgrade to 2.1.4
Mitigation:
all users should upgrade to 2.1.4
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache streampark |
|
| CPEs | cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache streampark |
Fri, 13 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Apache Software Foundation
Apache Software Foundation apache Streampark |
|
| References |
| |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-13T17:04:30.274Z
Reserved: 2024-03-15T03:21:44.446Z
Link: CVE-2024-29070
Updated: 2024-09-13T17:04:30.274Z
Status : Analyzed
Published: 2024-07-23T09:15:02.503
Modified: 2025-07-10T18:24:57.027
Link: CVE-2024-29070
No data.
OpenCVE Enrichment
No data.
Weaknesses