CVE-2025-54947

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access. This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:*

History

15 Dec 2025, 17:20

Type Values Removed Values Added
References () https://lists.apache.org/thread/kdntmzyzrco75x9q6mc6s8lty1fxmog1 - () https://lists.apache.org/thread/kdntmzyzrco75x9q6mc6s8lty1fxmog1 - Mailing List
References () http://www.openwall.com/lists/oss-security/2025/12/12/3 - () http://www.openwall.com/lists/oss-security/2025/12/12/3 - Mailing List
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 9.8
First Time Apache streampark
Apache
CPE cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:*
CWE CWE-798

12 Dec 2025, 19:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/12/12/3 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

12 Dec 2025, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-12 15:15

Updated : 2025-12-15 17:20


NVD link : CVE-2025-54947

Mitre link : CVE-2025-54947

CVE.ORG link : CVE-2025-54947


JSON object : View

Products Affected

apache

  • streampark
CWE
CWE-321

Use of Hard-coded Cryptographic Key

CWE-798

Use of Hard-coded Credentials