Vulnerabilities > Apache > Storm

DATE CVE VULNERABILITY TITLE RISK
2023-11-23 CVE-2023-43123 Unspecified vulnerability in Apache Storm
On unix-like systems, the temporary directory is shared between all user.
local
low complexity
apache
5.5
2021-10-25 CVE-2021-38294 OS Command Injection vulnerability in Apache Storm
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4.
network
low complexity
apache CWE-78
critical
9.8
2021-10-25 CVE-2021-40865 Deserialization of Untrusted Data vulnerability in Apache Storm
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE).
network
low complexity
apache CWE-502
critical
9.8
2019-07-26 CVE-2019-0202 Information Exposure Through Log Files vulnerability in Apache Storm
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm.
network
low complexity
apache CWE-532
7.5
2019-07-26 CVE-2018-11779 Deserialization of Untrusted Data vulnerability in Apache Storm
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
network
low complexity
apache CWE-502
critical
9.8
2018-07-10 CVE-2018-1331 Unspecified vulnerability in Apache Storm
In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.
network
low complexity
apache
8.8
2018-06-05 CVE-2018-8008 Path Traversal vulnerability in Apache Storm
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames.
local
low complexity
apache CWE-22
5.5
2018-06-05 CVE-2018-1332 Information Exposure vulnerability in Apache Storm
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.
network
low complexity
apache CWE-200
6.5
2017-10-30 CVE-2014-0115 Path Traversal vulnerability in Apache Storm 0.9.0.1
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a ..
network
low complexity
apache CWE-22
7.5
2017-08-09 CVE-2017-9799 Unspecified vulnerability in Apache Storm
It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user.
network
low complexity
apache
8.8