Security Advisory

CVE-2022-45802

9.8
CRITICAL

Vulnerability Description

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
Published Date May 1, 2023
Official Source NIST NVD Advisory