#VU120171 Use of hard-coded cryptographic key in Apache StreamPark - CVE-2025-54947
Published: December 17, 2025
Apache StreamPark
Apache Foundation
Description
The vulnerability allows a remote attacker gain access to sensitive information.
The vulnerability exists due to application uses a fixed, immutable key for encryption instead of dynamically generating or securely configuring the key. A remote attacker can obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information.