Skip to main content

Vendor/product archive

apache / streampipes CVEs

Beta · best-effort

7 CVEs tagged to apache / streampipes1 Critical, 3 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2025-47411

Published Jan 1, 2026

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-24778

Published Mar 3, 2025

Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31411

Published Jul 17, 2024

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RC…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31979

Published Jul 17, 2024

Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30471

Published Jul 17, 2024

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of mul…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-29868

Published Jun 24, 2024

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an atta…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31469

Published Jun 23, 2023

A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1