Apache StreamPipes Flaw Lets Anyone Become Admin
ID: 6f527af7-2a1f-5fa0-a2fe-fa0f71ed55cf
STIX ID: report--6f527af7-2a1f-5fa0-a2fe-fa0f71ed55cf
Feed Name: TechRepublic Security
Threat Score
A critical authentication vulnerability (CVE-2025-47411) in Apache StreamPipes allows attackers to modify JWT username values to gain administrative privileges, exposing proprietary, operational, and customer data across affected versions (0.69.0–0.97.0); proof-of-concept exploits are reportedly circulating and Apache has released version 0.98.0 to fix the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
