oss-sec mailing list archives

CVE-2024-29178: Apache StreamPark: FreeMarker SSTI RCE Vulnerability


From: Huajie Wang <benjobs () apache org>
Date: Thu, 18 Jul 2024 10:11:22 +0000

Severity: moderate

Affected versions:

- Apache StreamPark 1.0.0 before 2.1.4

Description:

On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code 
Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a 
moderate-impact vulnerability.

Mitigation:

all users should upgrade to 2.1.4

Credit:

L0ne1y (reporter)

References:

https://streampark.incubator.apache.org
https://www.cve.org/CVERecord?id=CVE-2024-29178


Current thread: