On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even after logout.
Mitigation:
all users should upgrade to 2.1.4
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache streampark |
|
CPEs | cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache streampark |
Fri, 13 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | ||
Vendors & Products |
Apache Software Foundation
Apache Software Foundation apache Streampark |
|
References |
| |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: apache
Published: 2024-07-23T08:13:41.408Z
Updated: 2024-09-13T17:04:30.274Z
Reserved: 2024-03-15T03:21:44.446Z
Link: CVE-2024-29070

Updated: 2024-09-13T17:04:30.274Z

Status : Analyzed
Published: 2024-07-23T09:15:02.503
Modified: 2025-07-10T18:24:57.027
Link: CVE-2024-29070

No data.