icon

We found results for “

CVE-2024-29120

Good to know:

icon

Date: July 17, 2024

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc.  Mitigation: all users should upgrade to 2.1.4

Language: Java

Severity Score

Severity Score

Weakness Type (CWE)

Improper Removal of Sensitive Information Before Storage or Transfer

CWE-212

Insecure Storage of Sensitive Information

CWE-922

Top Fix

icon

Upgrade Version

Upgrade to version v2.1.4

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us