CVE-2024-31979 Overview
CVE-2024-31979 is a Server-Side Request Forgery (SSRF) vulnerability [CWE-918] in Apache StreamPipes affecting the pipeline element installation process. The flaw exists in all versions through 0.93.0. StreamPipes previously allowed users to configure custom endpoints from which to install additional pipeline elements, but these endpoints were not properly validated. An authenticated attacker can abuse this behavior to force StreamPipes to issue arbitrary HTTP GET requests to attacker-chosen addresses, including internal network resources. Apache has released version 0.95.0 to remediate the issue.
Critical Impact
Authenticated attackers can coerce the StreamPipes server to send HTTP GET requests to arbitrary internal or external hosts, enabling internal network reconnaissance and interaction with services otherwise unreachable from the public network.
Affected Products
- Apache StreamPipes versions through 0.93.0
- Deployments exposing the pipeline element installation feature to authenticated users
- Self-hosted StreamPipes instances with network access to internal services
Discovery Timeline
- 2024-07-17 - CVE-2024-31979 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-31979
Vulnerability Analysis
The vulnerability resides in the StreamPipes functionality that allows users to configure custom endpoints for installing additional pipeline elements. StreamPipes accepts a user-supplied URL and performs an outbound HTTP GET request to retrieve element metadata. The input validation layer does not restrict the target host, scheme, or address range. As a result, an authenticated user can supply URLs pointing to internal IP ranges (such as 127.0.0.1, 169.254.169.254, or RFC1918 addresses) and have the server-side process reach them on the attacker's behalf. This is a textbook SSRF primitive classified under [CWE-918].
Root Cause
The root cause is missing allow-list validation on the endpoint parameter used during pipeline element installation. StreamPipes trusted the configured URL and dispatched the HTTP GET request without verifying that the destination resolved to an approved external host. Neither DNS rebinding protection nor network-layer filtering was enforced at the application layer.
Attack Vector
An authenticated attacker with low privileges issues a request to configure a custom pipeline element endpoint. The attacker substitutes the URL with an internal address, such as a cloud metadata service, an internal admin console, or a service bound to localhost. StreamPipes performs the GET request from its own network context. The response or side effects can leak information about internal infrastructure, probe reachable services, or interact with unauthenticated internal endpoints. The vulnerability does not require user interaction beyond the attacker's own authenticated session. See the Apache Mailing List Discussion and the Openwall OSS-Security Update for additional detail.
Detection Methods for CVE-2024-31979
Indicators of Compromise
- Outbound HTTP GET requests from the StreamPipes server to internal RFC1918 addresses, 127.0.0.1, or cloud metadata endpoints such as 169.254.169.254
- Pipeline element installation configuration changes referencing unexpected or non-standard endpoint URLs
- StreamPipes application logs showing failed or unusual connections to internal services during element installation
Detection Strategies
- Review StreamPipes audit logs for custom endpoint configuration events and correlate them with the authenticated user and source IP
- Inspect egress proxy logs for requests originating from the StreamPipes host targeting non-public address ranges
- Alert on any outbound traffic from StreamPipes to cloud instance metadata services
Monitoring Recommendations
- Enable verbose logging of pipeline element installation requests, including the full configured URL
- Forward StreamPipes host network telemetry to a centralized analytics platform for baseline comparison
- Monitor for anomalous DNS lookups originating from the StreamPipes server process
How to Mitigate CVE-2024-31979
Immediate Actions Required
- Upgrade Apache StreamPipes to version 0.95.0 or later, which contains the fix
- Audit existing pipeline element endpoint configurations for suspicious or unauthorized URLs
- Rotate any credentials or tokens that could have been exposed via internal metadata endpoints
- Restrict access to the StreamPipes administrative and pipeline element configuration interfaces to trusted users only
Patch Information
The Apache StreamPipes project addressed CVE-2024-31979 in version 0.95.0. Operators should plan an upgrade from any version through 0.93.0. Refer to the Apache Mailing List Discussion for release details.
Workarounds
- Place StreamPipes behind an egress proxy that restricts outbound HTTP requests to an allow-list of approved package or extension repositories
- Use network segmentation to prevent the StreamPipes host from reaching sensitive internal services, cloud metadata endpoints, and administrative consoles
- Disable or restrict the custom pipeline element installation feature where not required by business workflows
# Example egress firewall rule blocking StreamPipes access to cloud metadata service
iptables -A OUTPUT -m owner --uid-owner streampipes -d 169.254.169.254 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.