CVE 8.1 HIGH

Apache StreamPipes: Leverage of User ID for Privilege Escalation_CVE-2025-47411

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. 

This vulnerability allows an attacker to gain administrative control over the application by manipulating JWT tokens, which can lead to data tampering, unauthorized access and other security issues.






This issue affects Apache StreamPipes: through 0.97.0.

Users are recommended to upgrade to version 0.98.0, which fixes the issue.

Basic Information

ID CVE-2025-47411
Source apache
Published Jan 1, 2026 at 16:41
Modified Jan 5, 2026 at 15:15

Affected Product

Vendor Apache Software Foundation
Product Apache StreamPipes
Version 0.69.0
Affected Versions Apache Software Foundation Apache StreamPipes 0.69.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.