CVE-2024-48988

CVE-2024-48988: Apache StreamPark: SQL injection vulnerability

Vendor Apache Software Foundation
Product Apache StreamPark
Weakness CWE-564
Published August 22, 2025
Last update November 4, 2025

CVSS base score

What the vulnerability does

Description

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (SpringBoot platform) and does not involve Maven artifacts. It can only be exploited after a user has successfully logged into the platform (implying that the attacker would first need to compromise the login authentication). As a result, the associated risk is considered relatively low.

Key dates

Disclosure timeline

August 22, 2025 CVE published
November 4, 2025 Record updated