Vulnerability Details CVE-2025-54981
Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data
This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.
Users are recommended to upgrade to version 2.1.7, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.3%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-54981
-
cpe:2.3:a:apache:streampark:2.0.0
-
cpe:2.3:a:apache:streampark:2.1.0
-
cpe:2.3:a:apache:streampark:2.1.1
-
cpe:2.3:a:apache:streampark:2.1.2
-
cpe:2.3:a:apache:streampark:2.1.3
-
cpe:2.3:a:apache:streampark:2.1.4
-
cpe:2.3:a:apache:streampark:2.1.5
-
cpe:2.3:a:apache:streampark:2.1.6