{"id":"CVE-2022-45802","aliases":["GHSA-6874-289g-f7h7"],"url":"https://o3.security/vulnerability/CVE-2022-45802","summary":"Apache StreamPark (incubating): Upload any file to any directory","details":"Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later\n\n\n\n\n\n\n","published":"2023-05-01T14:04:57.625Z","modified":"2026-08-12T13:32:19.905506Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01308,"percentile":0.67959,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.streampark:streampark-common_2.12","fixedVersion":"2.0.0"},{"ecosystem":"Maven","name":"org.apache.streampark:streampark-common_2.11","fixedVersion":"2.0.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/45xxx/CVE-2022-45802.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/thwl1v2h6r3c21x1qwff08o57qzjnst6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-45802"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:32:19.905506Z"}}