This issue affects Apache StreamPark: from 2.1.4 before 2.1.6.
Users are recommended to upgrade to version 2.1.6, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6wwv-6mm3-pp76 | Apache StreamPark contains an Incorrect Execution-Assigned Permissions vulnerability |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 28 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:* |
Mon, 20 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache streampark |
|
| Vendors & Products |
Apache
Apache streampark |
Fri, 10 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 10 Oct 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. | |
| Title | Apache StreamPark: Authenticated users can trigger remote command execution | |
| Weaknesses | CWE-279 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-04T21:09:55.311Z
Reserved: 2025-03-13T15:21:07.661Z
Link: CVE-2025-30001
Updated: 2025-11-04T21:09:55.311Z
Status : Modified
Published: 2025-10-10T10:15:33.960
Modified: 2025-11-04T22:16:09.290
Link: CVE-2025-30001
No data.
OpenCVE Enrichment
Updated: 2025-10-20T16:25:28Z
Github GHSA