← Vulnerability feed

Vulnerability record · CVE-2024-29070 · published 23 July 2024

CVE-2024-29070: Apache streampark insufficient session expiration vulnerability

Apache · Streampark

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even after logout. Mitigation: all users should upgrade to 2.1.4

9.1 CVSS 3.1 Critical EPSS 0.79% · top 45.6% CWE-613 · Insufficient session expiration
9.1CVSS 3.1 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even after logout. Mitigation: all users should upgrade to 2.1.4

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-29070 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54947Apache streampark hard-coded credentials vulnerabilityIn Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…EPSS 0.48%9.8CVE-2022-45802Apache streampark unrestricted file upload vulnerabilityStreampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…EPSS 1.3%9.1CVE-2022-46365Apache streampark improper input validation vulnerabilityApache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …EPSS 1.5%8.8CVE-2024-29178Apache streampark code injection vulnerabilityOn versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …EPSS 1.2%8.1CVE-2023-52290Apache streampark sql injection vulnerabilityIn streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en…EPSS 0.64%7.6CVE-2024-48988Apache streampark sql injection vulnerabilitySQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to …EPSS 0.59%7.5CVE-2025-54981Apache streampark broken cryptographic algorithm vulnerabilityWeak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, inclu…EPSS 0.24%7.3CVE-2025-30001Apache streampark vulnerabilityIncorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2024-29070), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.