Headline
GHSA-pm73-x2h5-cmj3: Apache StreamPipes Improper Privilege Management vulnerability
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by upgrading to StreamPipes 0.92.0.
Apache StreamPipes Improper Privilege Management vulnerability
Moderate severity GitHub Reviewed Published Jun 23, 2023 to the GitHub Advisory Database • Updated Jun 27, 2023
Related news
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by upgrading to StreamPipes 0.92.0.