CVE-2014-0115
published 2017-10-30CVE-2014-0115: Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
5.25%
91.6th percentile
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | storm | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Storm log viewer path traversal vulnerability
osv·2022-05-17
CVE-2014-0115 [HIGH] Apache Storm log viewer path traversal vulnerability
Apache Storm log viewer path traversal vulnerability
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a `..` (dot dot) in the file parameter to log.
GHSA
Apache Storm log viewer path traversal vulnerability
ghsa·2022-05-17
CVE-2014-0115 [HIGH] CWE-22 Apache Storm log viewer path traversal vulnerability
Apache Storm log viewer path traversal vulnerability
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a `..` (dot dot) in the file parameter to log.
No detection rules found.
No public exploits indexed.
https://issues.apache.org/jira/browse/STORM-269https://mail-archives.apache.org/mod_mbox/storm-dev/201404.mbox/%3CJIRA.12704141.1395964296891.201561.1398799995645%40arcas%3Ehttps://issues.apache.org/jira/browse/STORM-269https://mail-archives.apache.org/mod_mbox/storm-dev/201404.mbox/%3CJIRA.12704141.1395964296891.201561.1398799995645%40arcas%3E
2017-10-30
Published