← Vulnerability feed

Vulnerability record · CVE-2025-54947 · published 12 December 2025

CVE-2025-54947: Apache streampark hard-coded credentials vulnerability

Apache · Streampark

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access. This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.

9.8 CVSS 3.1 Critical EPSS 0.48% · top 61.2% CWE-321 · CWE-321CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access. This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54947 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-45802Apache streampark unrestricted file upload vulnerabilityStreampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…EPSS 1.3%9.1CVE-2024-29070Apache streampark insufficient session expiration vulnerabilityOn versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" …EPSS 0.79%9.1CVE-2022-46365Apache streampark improper input validation vulnerabilityApache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …EPSS 1.5%8.8CVE-2024-29178Apache streampark code injection vulnerabilityOn versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …EPSS 1.2%8.1CVE-2023-52290Apache streampark sql injection vulnerabilityIn streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en…EPSS 0.64%7.6CVE-2024-48988Apache streampark sql injection vulnerabilitySQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to …EPSS 0.59%7.5CVE-2025-54981Apache streampark broken cryptographic algorithm vulnerabilityWeak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, inclu…EPSS 0.24%7.3CVE-2025-30001Apache streampark vulnerabilityIncorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2025-54947), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.