Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.streampark/streampark
  4. ›
  5. CVE-2025-54947

CVE-2025-54947: Apache StreamPark has a hard-coded encryption key

December 12, 2025

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs because the system uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access.

This issue affects Apache StreamPark: from 2.0.0 before 2.1.7.

Users are recommended to upgrade to version 2.1.7, which fixes the issue.

References

  • github.com/advisories/GHSA-prv5-c2px-j9q3
  • github.com/apache/streampark
  • github.com/apache/streampark/commit/39034db0c806168afa82e58e4f376e1e3c3b73e4
  • lists.apache.org/thread/kdntmzyzrco75x9q6mc6s8lty1fxmog1
  • nvd.nist.gov/vuln/detail/CVE-2025-54947

Code Behaviors & Features

Detect and mitigate CVE-2025-54947 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.0.0 before 2.1.7

Fixed versions

  • 2.1.7

Solution

Upgrade to version 2.1.7 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-321: Use of Hard-coded Cryptographic Key

Source file

maven/org.apache.streampark/streampark/CVE-2025-54947.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 14 Dec 2025 00:19:12 +0000.