stormGHSA-6768-mcjc-8223
Command injection leading to Remote Code Execution in Apache Storm
Critical9.8CVE-2021-38294 · Published Oct 27, 2021 · updated Nov 8, 2023
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.storm:storm Maven | >= 2.2.0, < 2.2.1 | 2.2.1 |
| >= 2.0.0, < 2.1.1 | 2.1.1 | |
| >= 1.0.0, < 1.2.4 | 1.2.4 |
Details and references
More storm advisories
All storm| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Apache Storm log viewer path traversal vulnerability | High7.5 | No fix yet |
| May 142022 | Apache Storm remote code execution vulnerability | Critical9.8 | 0.10.0-beta1 |
| Oct 272021 | Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm | Critical9.8 | 1.2.4+2 more |