CVE-2025-54947

I

n Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access. This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.

Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:*

History

15 Dec 2025, 17:20

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-12 15:15

Updated : 2025-12-15 17:20


NVD link : CVE-2025-54947

Mitre link : CVE-2025-54947

CVE.ORG link : CVE-2025-54947


JSON object : View

Products Affected
CWE
CWE-321

Use of Hard-coded Cryptographic Key

CWE-798

Use of Hard-coded Credentials