Apache StreamPark (incubating): Upload any file to any directory
Vulnerability Description
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-45802
Credits & Attribution
No credits recorded in the NVD database.
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →