CVE-2022-46365
Apache StreamPark Improper Input Validation vulnerability
9.1
CRITICAL
CVSS 3.1
EPSS 1.5%
描述
Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, This will allow malicious attackers to send any username to modify and reset the account, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later.
如何修補 CVE-2022-46365
要修補 CVE-2022-46365,請將受影響套件升級到下列已修補版本。
- —升級至 2.0.0 或更新版本
CVE-2022-46365 正在被利用嗎?
低 — EPSS 為 1.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 1.0.0, < 2.0.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |