PT-2025-34477 · Apache · Apache Streampark

Published

2025-08-22

·

Updated

2025-08-23

·

CVE-2024-48988

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Apache StreamPark versions 2.1.4 through 2.1.5
Description: A SQL Injection vulnerability exists in Apache StreamPark. This issue is present only in the distribution package (SpringBoot platform) and does not involve Maven artifacts. Exploitation requires successful user login authentication, resulting in a relatively low risk.
Recommendations: Upgrade to version 2.1.6.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-48988

Affected Products

Apache Streampark