CVE-2025-47411
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator. This vulnerability allows an attacker to gain administrative control over the application by manipulating JWT tokens, which can lead to data tampering, unauthorized access and other security issues. This issue affects Apache StreamPipes: through 0.97.0. Users are recommended to upgrade to version 0.98.0, which fixes the issue.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 16.23% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- apache/streampipes
- Source
- security@apache.org
References
- https://lists.apache.org/thread/lngko4ht2ok3o0rk9h0clgm4kb0lmt36Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/12/29/14Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.