PT-2025-50940 · Unknown · Apache Streampark

CVE-2025-54981

·

Published

2025-12-12

·

Updated

2025-12-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache StreamPark versions 2.0.0 through 2.1.6
Description The software utilizes an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, potentially exposing authentication data.
Recommendations Upgrade to version 2.1.7 to resolve the issue.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54981
GHSA-749J-2HP6-8CXM

Affected Products

Apache Streampark