PT-2025-50940 · Unknown · Apache Streampark

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-54981

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache StreamPark versions 2.0.0 through 2.1.6
Description The software utilizes an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, potentially exposing authentication data.
Recommendations Upgrade to version 2.1.7 to resolve the issue.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2025-54981
GHSA-749J-2HP6-8CXM

Affected Products

Apache Streampark