-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unrestricted file uploads (CWE-434). The analysis focused on file upload handlers in the Java backend since the Maven package is affected. The 0.95.0 release notes mention fixes related to file upload functionality (issues #2221, #2326), suggesting the file upload handler lacked proper validation. The function name and path are inferred from common Java web app patterns and Apache StreamPipes' package structure. Confidence is medium due to reliance on vulnerability patterns and release notes without direct access to the patched code diff.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.streampipes:streampipes-parent | maven | < 0.95.0 | 0.95.0 |
| streampipes | pip | < 0.95.0 | 0.95.0 |
Ongoing coverage of React2Shell