PT-2024-5227 · Apache · Apache Streampipes

·

CVE-2024-30471

·

Published

2024-07-16

·

Updated

2024-08-01

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Apache StreamPipes versions through 0.93.0
Description: A Time-of-check Time-of-use (TOCTOU) Race Condition issue exists in the user self-registration component of Apache StreamPipes. This allows an attacker to potentially create multiple accounts with the same email address, resulting in the corruption of StreamPipes' user management. The issue can be exploited by a remote attacker to disrupt the user management process by creating multiple users with the same email address.
Recommendations: Upgrade to version 0.95.0 to fix the issue.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05792
CVE-2024-30471
GHSA-2QPH-V9P2-Q2GV
PYSEC-2024-172

Affected Products

Apache Streampipes