Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:48182
HistoryJul 23, 2024 - 6:29 a.m.

Insecure Direct Object Reference (IDOR)

2024-07-2306:29:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3
insecure direct object reference
apache streampark
vulnerability
access control
authorization tokens
attack
users' information
flink
executesql
configuration

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

29.2%

org.apache.streampark, streampark is vulnerable to Insecure Direct Object Reference (IDOR). The vulnerability is due to insufficient access control due to improper handling of authorization tokens, allowing attackers to manually request and view all users’ flink information, including executeSQL and config.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

29.2%

Related for VERACODE:48182