In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access.
This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.
Users are recommended to upgrade to version 2.1.7, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/kdntmzyzrco75x9q6mc6s8lty1fxmog1 | Mailing List |
| http://www.openwall.com/lists/oss-security/2025/12/12/3 | Mailing List |
Configurations
History
15 Dec 2025, 17:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://lists.apache.org/thread/kdntmzyzrco75x9q6mc6s8lty1fxmog1 - Mailing List | |
| References | () http://www.openwall.com/lists/oss-security/2025/12/12/3 - Mailing List | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| First Time |
Apache streampark
Apache |
|
| CPE | cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:* | |
| CWE | CWE-798 |
12 Dec 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
12 Dec 2025, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-12 15:15
Updated : 2025-12-15 17:20
NVD link : CVE-2025-54947
Mitre link : CVE-2025-54947
CVE.ORG link : CVE-2025-54947
JSON object : View
Products Affected
apache
- streampark
