Launch Week Day 1: Announcing Security Design Review
HIGH 8.8 Maven

Apache StreamPipes Improper Privilege Management vulnerability

GHSA-pm73-x2h5-cmj3 · CVE-2023-31469

Published · Modified

Description

A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles.
The issue is resolved by upgrading to StreamPipes 0.92.0.

Ready to move

Start Securing

Free, no credit card | First findings in minutes