Apache StreamPark (incubating): Logic error causing any account reset
CVE-2022-46365
9.1CRITICAL
What is CVE-2022-46365?
A security vulnerability in Apache StreamPark version 1.0.0 allows an authenticated user to exploit the profile modification functionality. When logged in, the application fails to verify if the username provided during a profile update belongs to the current user. This oversight allows attackers to send arbitrary usernames, potentially enabling them to modify or reset the accounts of other users. Users should upgrade to Apache StreamPark version 2.0.0 or later to mitigate this issue.
Affected Version(s)
Apache StreamPark (incubating) 1.0.0 < 2.0.0