This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.
Users are recommended to upgrade to version 2.1.7, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-749j-2hp6-8cxm | Apache StreamPark uses a Weak Encryption Algorithm |
Mon, 15 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:* |
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache streampark |
|
| Vendors & Products |
Apache
Apache streampark |
Fri, 12 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 12 Dec 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 12 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue. | |
| Title | Apache StreamPark: Weak Encryption Algorithm in StreamPark | |
| Weaknesses | CWE-327 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-12-12T19:27:16.118Z
Reserved: 2025-08-04T10:13:02.810Z
Link: CVE-2025-54981
Updated: 2025-12-12T18:04:58.530Z
Status : Analyzed
Published: 2025-12-12T15:15:53.703
Modified: 2025-12-15T17:19:19.633
Link: CVE-2025-54981
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:16:19Z
Github GHSA