CVE-2026-41081
- EPSS 0.11%
- Veröffentlicht 27.04.2026 13:10:45
- Zuletzt bearbeitet 28.04.2026 19:46:06
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authenti...
CVE-2026-35337
- EPSS 0.27%
- Veröffentlicht 13.04.2026 09:11:06
- Zuletzt bearbeitet 15.04.2026 15:54:21
Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInp...
CVE-2026-35565
- EPSS 0.01%
- Veröffentlicht 13.04.2026 09:10:17
- Zuletzt bearbeitet 15.04.2026 15:53:49
Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and gro...
CVE-2023-43123
- EPSS 0.03%
- Veröffentlicht 23.11.2023 10:15:07
- Zuletzt bearbeitet 13.02.2025 17:17:12
On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern...
CVE-2021-40865
- EPSS 46.22%
- Veröffentlicht 25.10.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:24:58
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users sho...
CVE-2021-38294
- EPSS 82.06%
- Veröffentlicht 25.10.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:44
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to...
CVE-2019-0202
- EPSS 0.64%
- Veröffentlicht 26.07.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:16:28
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to...
CVE-2018-11779
- EPSS 1.47%
- Veröffentlicht 26.07.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 03:44:01
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
CVE-2018-1331
- EPSS 5.11%
- Veröffentlicht 10.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:38
In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.
CVE-2018-1332
- EPSS 0.43%
- Veröffentlicht 05.06.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:38
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.