CyberSec.Space Logo
Back to CVE Browser

CVE-2024-34457

MEDIUM
6.5
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-07-22
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4

Affected Platforms (CPE)

📦
Apache

Streampark

< 2.1.4

References & Advisories

Related Vulnerabilities