oss-sec mailing list archives

CVE-2024-29070: Apache StreamPark: session not invalidated after logout


From: Huajie Wang <benjobs () apache org>
Date: Mon, 22 Jul 2024 15:25:08 +0000

Severity: moderate

Affected versions:

- Apache StreamPark 1.0.0 before 2.1.4

Description:

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend 
service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests 
and access data even after logout.

Mitigation:

all users should upgrade to 2.1.4

Credit:

L0ne1y (reporter)

References:

https://streampark.incubator.apache.org
https://www.cve.org/CVERecord?id=CVE-2024-29070


Current thread: