Apache Software Foundation Apache Storm vulnerabilities

7 known vulnerabilities affecting apache_software_foundation/apache_storm.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-43123MEDIUMCVSS 5.5≥ 2.0.0, < 2.6.02023-11-23
CVE-2023-43123 [MEDIUM] CWE-200 CVE-2023-43123: On unix-like systems, the temporary directory is shared between all user. As such, writing to this d On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method File.createTempFile on unix-like systems creates a file with pr
cvelistv5nvd
CVE-2021-40865CRITICALCVSS 9.8≥ v1.0.0, < Apache Storm *≥ Apache Storm, < v1.2.42021-10-25
CVE-2021-40865 [CRITICAL] CWE-502 CVE-2021-40865: An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4
cvelistv5nvd
CVE-2021-38294CRITICALCVSS 9.8≥ v1.0.0, < Apache Storm*≥ Apache Storm, < v1.2.42021-10-25
CVE-2021-38294 [CRITICAL] CWE-74 CVE-2021-38294: A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x p A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.
cvelistv5nvd
CVE-2018-1331HIGHCVSS 8.8v0.10.0 through 0.10.2v1.0.0 through 1.0.6+2 more2018-07-10
CVE-2018-1331 [HIGH] CVE-2018-1331: In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1 In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.
cvelistv5nvd
CVE-2018-8008MEDIUMCVSS 5.5vApache Storm 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier2018-06-05
CVE-2018-8008 [MEDIUM] CWE-22 CVE-2018-8008: Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an a Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extra
cvelistv5nvd
CVE-2018-1332MEDIUMCVSS 6.5vApache Storm 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier2018-06-05
CVE-2018-1332 [MEDIUM] CWE-200 CVE-2018-1332: Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vu Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.
cvelistv5nvd
CVE-2017-9799HIGHCVSS 8.8v1.0.0 through 1.0.3v1.1.02017-08-09
CVE-2017-9799 [HIGH] CVE-2017-9799: It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1. It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised.
cvelistv5nvd