CVE-2024-29120

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc.  Mitigation: all users should upgrade to 2.1.4
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-07-17 15:15

Updated : 2024-07-18 12:28


NVD link : CVE-2024-29120

Mitre link : CVE-2024-29120

CVE.ORG link : CVE-2024-29120


JSON object : View

Products Affected

No product.

CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer