CVE-2024-34457
22.07.2024, 10:15
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4Enginsight
Vendor | Product | Version |
---|---|---|
apache | streampark | 𝑥 < 2.1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration