← Vulnerability feed

Vulnerability record · CVE-2025-30001 · published 10 October 2025

CVE-2025-30001: Apache streampark vulnerability

Apache · Streampark

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.

7.3 CVSS 3.1 High EPSS 0.55% · top 56.0% CWE-279 · CWE-279
7.3CVSS 3.1 base score
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-30001 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54947Apache streampark hard-coded credentials vulnerabilityIn Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…EPSS 0.48%9.8CVE-2022-45802Apache streampark unrestricted file upload vulnerabilityStreampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…EPSS 1.3%9.1CVE-2024-29070Apache streampark insufficient session expiration vulnerabilityOn versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" …EPSS 0.79%9.1CVE-2022-46365Apache streampark improper input validation vulnerabilityApache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …EPSS 1.5%8.8CVE-2024-29178Apache streampark code injection vulnerabilityOn versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …EPSS 1.2%8.1CVE-2023-52290Apache streampark sql injection vulnerabilityIn streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en…EPSS 0.64%7.6CVE-2024-48988Apache streampark sql injection vulnerabilitySQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to …EPSS 0.59%7.5CVE-2025-54981Apache streampark broken cryptographic algorithm vulnerabilityWeak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, inclu…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2025-30001), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.