Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Apache StreamPipes

CVE-2024-30471

3.7LOW

Key Information

Vendor
Apache
Status
Apache Streampipes
Vendor
CVE Published:
17 July 2024

Summary

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with the same email address until the email address is registered, creating many identical users and corrupting StreamPipe's user management. This issue affects Apache StreamPipes: through 0.93.0.

Users are recommended to upgrade to version 0.95.0, which fixes the issue.

Affected Version(s)

Apache StreamPipes <= 0.93.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

TonyNT from VNPT-NET
.