PT-2023-23347 · Apache · Apache Streampipes

·

CVE-2023-31469

·

Published

2023-06-23

·

Updated

2024-10-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache StreamPipes versions 0.69.0 through 0.91.0
Description A REST interface in Apache StreamPipes was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles.
Recommendations For Apache StreamPipes versions 0.69.0 through 0.91.0, upgrade to StreamPipes 0.92.0 to resolve the issue. As a temporary workaround, consider restricting access to the REST interface to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-31469
GHSA-PM73-X2H5-CMJ3

Affected Products

Apache Streampipes