CVE-2022-45802
CWE-434Published: May 1, 2023· Updated: Jun 17, 2026
Official Description
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
Risk Analysis
Apache StreamPark lacks mandatory file type verification for application uploads, allowing users to upload high-risk files to arbitrary directories. This critical vulnerability enables remote code execution.
This vulnerability is remotely exploitable, though no public exploit is known.
Upgrade to Apache StreamPark version 2.0.0 or later.
Technical Analysis
CVE-2022-45802 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 9.8.
CVSS v3.1 Vector Breakdown
Affected Vendors & Products
Exploit & PoC Resources
All References (2)
Quick Facts
Related CVEs (CWE-434)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2022-45802 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts