CVE-2024-48988

Source
https://cve.org/CVERecord?id=CVE-2024-48988
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-48988.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-48988
Published
2025-08-22T19:15:38.217Z
Modified
2026-04-10T05:17:49.035564Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L CVSS Calculator
Summary
[none]
Details

SQL Injection vulnerability in Apache StreamPark.

This issue affects Apache StreamPark: from 2.1.4 before 2.1.6.

Users are recommended to upgrade to version 2.1.6, which fixes the issue.

This vulnerability is present only in the distribution package (SpringBoot platform) and does not involve Maven artifacts. It can only be exploited after a user has successfully logged into the platform (implying that the attacker would first need to compromise the login authentication). As a result, the associated risk is considered relatively low.

References

Affected packages

Git / github.com/apache/incubator-streampark

Affected ranges

Type
GIT
Repo
https://github.com/apache/incubator-streampark
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.1.4"
        },
        {
            "fixed": "2.1.6"
        }
    ]
}

Affected versions

v2.*
v2.1.4
v2.1.4-rc2
v2.1.5
v2.1.5-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-48988.json"