PT-2024-22741 · Unknown · Streampark

L0Ne1Y

·

Published

2024-07-17

·

Updated

2024-11-14

·

CVE-2024-29120

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Streampark versions prior to 2.1.4
Description The issue allows a user to obtain sensitive information, including usernames, passwords, and salt values of other users, after a successful login. This is due to the Backend service returning "Authorization" as the front-end authentication credential.
Recommendations For versions prior to 2.1.4, upgrade to version 2.1.4 to resolve the issue.

Fix

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-29120
GHSA-HCF8-5J78-887V

Affected Products

Streampark