In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access. This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.
History

Mon, 15 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798
CPEs cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:*

Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache streampark
Vendors & Products Apache
Apache streampark

Fri, 12 Dec 2025 19:30:00 +0000

Type Values Removed Values Added
References

Fri, 12 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Description In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access. This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.
Title Apache StreamPark: Use hard-coded key vulnerability
Weaknesses CWE-321
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-12-12T15:11:38.279Z

Updated: 2025-12-12T18:48:51.364Z

Reserved: 2025-08-01T09:20:24.478Z

Link: CVE-2025-54947

cve-icon Vulnrichment

Updated: 2025-12-12T18:04:57.034Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-12T15:15:53.577

Modified: 2025-12-15T17:20:46.757

Link: CVE-2025-54947

cve-icon Redhat

No data.