Apache StreamPark: FreeMarker SSTI RCE Vulnerability
High severity
GitHub Reviewed
Published
Jul 18, 2024
to the GitHub Advisory Database
•
Updated Feb 13, 2025
Description
Published by the National Vulnerability Database
Jul 18, 2024
Published to the GitHub Advisory Database
Jul 18, 2024
Reviewed
Feb 13, 2025
Last updated
Feb 13, 2025
On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability.
Mitigation:
all users should upgrade to 2.1.4
References