Apache

Storm

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 14.09.2026 14:19:16
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLoca...

  • EPSS 0.69%
  • Veröffentlicht 14.09.2026 14:18:09
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and predictable in ad...

  • EPSS 0.13%
  • Veröffentlicht 14.09.2026 14:16:45
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid of 0. Both s...

  • EPSS 0.14%
  • Veröffentlicht 14.09.2026 14:15:58
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the supervisor wr...

  • EPSS 0.48%
  • Veröffentlicht 14.09.2026 14:14:48
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.users` unset, t...

  • EPSS 0.61%
  • Veröffentlicht 14.09.2026 14:09:20
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, ...

  • EPSS 0.2%
  • Veröffentlicht 14.09.2026 14:02:07
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Control-Allow-Orig...

  • EPSS 0.29%
  • Veröffentlicht 27.04.2026 13:10:45
  • Zuletzt bearbeitet 28.04.2026 19:46:06

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authenti...

  • EPSS 1.01%
  • Veröffentlicht 13.04.2026 09:11:06
  • Zuletzt bearbeitet 15.04.2026 15:54:21

Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInp...

  • EPSS 0.47%
  • Veröffentlicht 13.04.2026 09:10:17
  • Zuletzt bearbeitet 15.04.2026 15:53:49

Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and gro...