AI Score
Confidence
Low
EPSS
Percentile
57.1%
SSVC
Exploitation
none
Automatable
no
Technical Impact
total
On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server,Β The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability.
Mitigation:
all users should upgrade to 2.1.4
[
{
"cpes": [
"cpe:2.3:a:apache:streampark:1.0.0:-:*:*:*:*:*:*"
],
"vendor": "apache",
"product": "streampark",
"versions": [
{
"status": "affected",
"version": "1.0.0",
"lessThan": "2.1.4",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]