{"id":"GHSA-pm73-x2h5-cmj3","summary":"Apache StreamPipes Improper Privilege Management vulnerability","details":"A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles.\nThe issue is resolved by upgrading to StreamPipes 0.92.0.\n\n","aliases":["CVE-2023-31469"],"modified":"2023-11-09T05:41:20.563985Z","published":"2023-06-23T09:30:17Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-06-23T21:44:46Z","nvd_published_at":"2023-06-23T08:15:09Z","cwe_ids":["CWE-269"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-31469"},{"type":"PACKAGE","url":"https://github.com/apache/streampipes"},{"type":"WEB","url":"https://lists.apache.org/thread/c4y8kf9bzpf36v4bottfmd8tc9cxo19m"}],"affected":[{"package":{"name":"org.apache.streampipes:streampipes-parent","ecosystem":"Maven","purl":"pkg:maven/org.apache.streampipes/streampipes-parent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.69.0"},{"fixed":"0.92.0"}]}],"versions":["0.69.0","0.70.0","0.90.0","0.91.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-pm73-x2h5-cmj3/GHSA-pm73-x2h5-cmj3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}