CVE-2025-30001
BaseFortify
Publication date: 2025-10-10
Last updated on: 2025-11-04
Assigner: Apache Software Foundation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | streampark | From 2.1.4 (inc) to 2.1.6 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-279 | While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Incorrect Execution-Assigned Permissions issue in Apache StreamPark versions from 2.1.4 before 2.1.6. It means that the software incorrectly assigns permissions during execution, potentially allowing unauthorized actions.
How can this vulnerability impact me? :
The impact of this vulnerability could include unauthorized access or actions within Apache StreamPark due to incorrect permission assignments, which may lead to security risks such as data exposure or unauthorized operations.
What immediate steps should I take to mitigate this vulnerability?
Users are recommended to upgrade Apache StreamPark to version 2.1.6, which fixes the issue.