← Vulnerability feed

Vulnerability record · CVE-2024-48988 · published 22 August 2025

CVE-2024-48988: Apache streampark sql injection vulnerability

Apache · Streampark

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (SpringBoot platform) and does not involve Maven artifacts. It can only be exploited after a user has successfully logged into the platform (implying that the attacker would first need to compromise the login authentication). As a result, the associated risk is considered relatively low.

7.6 CVSS 3.1 High EPSS 0.59% · top 53.8% CWE-564 · CWE-564CWE-89 · SQL injection
7.6CVSS 3.1 base score
0.59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (SpringBoot platform) and does not involve Maven artifacts. It can only be exploited after a user has successfully logged into the platform (implying that the attacker would first need to compromise the login authentication). As a result, the associated risk is considered relatively low.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-48988 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54947Apache streampark hard-coded credentials vulnerabilityIn Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…EPSS 0.48%9.8CVE-2022-45802Apache streampark unrestricted file upload vulnerabilityStreampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…EPSS 1.3%9.1CVE-2024-29070Apache streampark insufficient session expiration vulnerabilityOn versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" …EPSS 0.79%9.1CVE-2022-46365Apache streampark improper input validation vulnerabilityApache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …EPSS 1.5%8.8CVE-2024-29178Apache streampark code injection vulnerabilityOn versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …EPSS 1.2%8.1CVE-2023-52290Apache streampark sql injection vulnerabilityIn streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en…EPSS 0.64%7.5CVE-2025-54981Apache streampark broken cryptographic algorithm vulnerabilityWeak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, inclu…EPSS 0.24%7.3CVE-2025-30001Apache streampark vulnerabilityIncorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2024-48988), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.