CVE-2024-29070: Apache Streampark
Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.
On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even after logout. Mitigation: all users should upgrade to 2.1.4
Affected products
- Apache Streampark: from 1.0.0, before 2.1.4 (fixed in 2.1.4)
Published 2024-07-23. Last modified 2026-06-17.