Incorrect Execution-Assigned Permissions Vulnerability in Apache StreamPark
CVE-2025-30001 
7.3HIGH
What is CVE-2025-30001?
A permissions vulnerability exists in Apache StreamPark that improperly assigns execution permissions, potentially exposing applications to unauthorized access and manipulation. Versions prior to 2.1.6 are affected. Users should upgrade to version 2.1.6 or later to mitigate the risk and enhance the security posture of their deployments.
Affected Version(s)
Apache StreamPark 2.1.4 < 2.1.6
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
 Low
Availability:
 Low
Attack Vector:
Network
Attack Complexity:
 Low
Privileges Required:
 None
User Interaction:
 None
Scope:
 Unchanged
Timeline
- Vulnerability published 
- Vulnerability Reserved 
Credit
Liufeng Yi ([email protected])