Apache

Storm

11 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 23.11.2023 10:15:07
  • Last modified 13.02.2025 17:17:12

On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern...

  • EPSS 46.22%
  • Published 25.10.2021 13:15:08
  • Last modified 21.11.2024 06:24:58

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users sho...

Exploit
  • EPSS 87.81%
  • Published 25.10.2021 13:15:07
  • Last modified 21.11.2024 06:16:44

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to...

  • EPSS 0.64%
  • Published 26.07.2019 00:15:11
  • Last modified 21.11.2024 04:16:28

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to...

  • EPSS 1.47%
  • Published 26.07.2019 00:15:10
  • Last modified 21.11.2024 03:44:01

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.

  • EPSS 5.37%
  • Published 10.07.2018 17:29:00
  • Last modified 21.11.2024 03:59:38

In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.

  • EPSS 0.43%
  • Published 05.06.2018 19:29:00
  • Last modified 21.11.2024 03:59:38

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.

  • EPSS 15.35%
  • Published 05.06.2018 19:29:00
  • Last modified 21.11.2024 04:13:04

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cp...

  • EPSS 0.66%
  • Published 30.10.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.

  • EPSS 0.89%
  • Published 09.08.2017 21:29:01
  • Last modified 20.04.2025 01:37:25

It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In...