On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even after logout.
Mitigation:
all users should upgrade to 2.1.4
Metrics
Affected Vendors & Products
References
History
Fri, 13 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | ||
Vendors & Products |
Apache Software Foundation
Apache Software Foundation apache Streampark |
|
References |
| |
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2024-07-23T08:13:41.408Z
Updated: 2024-09-13T17:04:30.274Z
Reserved: 2024-03-15T03:21:44.446Z
Link: CVE-2024-29070
Vulnrichment
Updated: 2024-09-13T17:04:30.274Z
NVD
Status : Awaiting Analysis
Published: 2024-07-23T09:15:02.503
Modified: 2024-11-21T09:07:29.507
Link: CVE-2024-29070
Redhat
No data.