Vulnerabilities > Apache > Streampipes > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-17 CVE-2024-31411 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Streampipes
Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and authorized users. This issue affects Apache StreamPipes: through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.
network
low complexity
apache CWE-434
8.8
2023-06-23 CVE-2023-31469 Improper Privilege Management vulnerability in Apache Streampipes
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access.
network
low complexity
apache CWE-269
8.8