{"id":"CVE-2022-45802","summary":"Apache StreamPark (incubating): Upload any file to any directory","details":"Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later\n\n\n\n\n\n\n","aliases":["GHSA-6874-289g-f7h7"],"modified":"2026-08-12T13:32:19.905506Z","published":"2023-05-01T14:04:57.625Z","database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-434"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/45xxx/CVE-2022-45802.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.0.0"},{"fixed":"2.0.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/45xxx/CVE-2022-45802.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/thwl1v2h6r3c21x1qwff08o57qzjnst6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-45802"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/streampark","events":[{"introduced":"0"},{"fixed":"6788ebae61d2f6d5122572229ce0a3a2555cc46d"}],"database_specific":{"cpe":"cpe:2.3:a:apache:streampark:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.0.0"}],"source":"CPE_RANGE"}}],"versions":["v2.0.0-rc6","v2.0.0-rc5","v2.0.0-rc4","v2.0.0-rc3","v2.0.0-rc2","v2.0.0-rc1","v1.2.3","v1.2.2","v1.2.1","v1.2.1-beta.1","v1.2.0","v1.1.1","V1.1.1","v1.1.0","v1.0.0"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/apache/streampark/commit/6788ebae61d2f6d5122572229ce0a3a2555cc46d","target":{"file":"streampark-console/streampark-console-service/src/main/java/org/apache/streampark/console/base/config/SwaggerConfig.java"},"deprecated":false,"digest":{"line_hashes":["71656344722943312801849449711893507401","64659150857662134098151502217020028558","262492611120373913243113230441025832054","202110951636850579304562443264749786966"],"threshold":0.9},"id":"CVE-2022-45802-56c2a45c","signature_type":"Line"},{"id":"CVE-2022-45802-ef6ff3ca","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/streampark/commit/6788ebae61d2f6d5122572229ce0a3a2555cc46d","target":{"file":"streampark-console/streampark-console-service/src/main/java/org/apache/streampark/console/base/config/SwaggerConfig.java","function":"apiInfo"},"deprecated":false,"digest":{"function_hash":"321823652206749881358323027347823640346","length":327}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-45802.json","vanir_signatures_modified":"2026-08-12T13:32:19Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}