Such a dangerous type might be an executable file that may lead to a remote code execution (RCE).
The unrestricted upload is only possible for authenticated and authorized users.
This issue affects Apache StreamPipes: through 0.93.0.
Users are recommended to upgrade to version 0.95.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6523-jf4r-c962 | Apache StreamPipes has potential remote code execution (RCE) via file upload |
Fri, 13 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Apache Software Foundation
Apache Software Foundation apache Streampipes |
|
| References |
| |
| Metrics |
ssvc
|
cvssV3_1
|
Thu, 22 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache streampipes |
|
| CPEs | cpe:2.3:a:apache:streampipes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache streampipes |
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-13T17:04:42.752Z
Reserved: 2024-04-03T10:48:25.894Z
Link: CVE-2024-31411
Updated: 2024-09-13T17:04:42.752Z
Status : Modified
Published: 2024-07-17T10:15:01.810
Modified: 2024-11-21T09:13:28.803
Link: CVE-2024-31411
No data.
OpenCVE Enrichment
No data.
Github GHSA