PYSEC-2025-66

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/streampipes/PYSEC-2025-66.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2025-66
Aliases
Published
2025-03-03T11:15:11Z
Modified
2025-07-08T15:58:16.731695Z
Summary
[none]
Details

Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know.

This issue affects Apache StreamPipes: through 0.95.1.

Users are recommended to upgrade to version 0.97.0 which fixes the issue.

References

Affected packages

PyPI / streampipes

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.97.0

Affected versions

0.*
0.0.2.dev0
0.91.0
0.92.0
0.93.0
0.95.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/streampipes/PYSEC-2025-66.yaml"