PT-2025-34477 · Apache · Apache Streampark

CVE-2024-48988

·

Published

2025-08-22

·

Updated

2025-08-23

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Apache StreamPark versions 2.1.4 through 2.1.5
Description: A SQL Injection vulnerability exists in Apache StreamPark. This issue is present only in the distribution package (SpringBoot platform) and does not involve Maven artifacts. Exploitation requires successful user login authentication, resulting in a relatively low risk.
Recommendations: Upgrade to version 2.1.6.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48988

Affected Products

Apache Streampark