Improper Privilege Management in Apache StreamPipes
CVE-2024-24778

6.5MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
3 March 2025

Summary

An improper privilege management vulnerability exists in the REST interface of Apache StreamPipes. This flaw enables registered users to access unauthorized resources, given that they are aware of the specific resource ID. The issue impacts all versions of StreamPipes up to and including 0.95.1. It is advisable for users to upgrade to version 0.97.0 or later to mitigate this risk and secure their applications.

Affected Version(s)

Apache StreamPipes 0 <= 0.95.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.