CVE-2025-54981
EUVD-2025-20308112.12.2025, 15:15
Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | streampark | 2.0.0 ≤ 𝑥 < 2.1.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration