org.apache.streampipes:streampipes-service-extensions@0.93.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.streampipes:streampipes-service-extensions package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Time-of-check Time-of-use (TOCTOU) Race Condition

Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition during the user self-registration process. An attacker can create multiple identical user accounts by repeatedly requesting account creation with the same email address before it is registered, leading to corruption in user management.

How to fix Time-of-check Time-of-use (TOCTOU) Race Condition?

Upgrade org.apache.streampipes:streampipes-service-extensions to version 0.95.0 or higher.

[0.93.0,0.95.0)