Skip to content
stormGHSA-6768-mcjc-8223

Command injection leading to Remote Code Execution in Apache Storm

Critical9.8CVE-2021-38294 · Published Oct 27, 2021 · updated Nov 8, 2023

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.storm:storm
Maven
>= 2.2.0, < 2.2.12.2.1
>= 2.0.0, < 2.1.12.1.1
>= 1.0.0, < 1.2.41.2.4
Details and references

More storm advisories

All storm
Advisory
Apache Storm log viewer path traversal vulnerability
High7.5May 17, 2022
Apache Storm remote code execution vulnerability
Critical9.8May 14, 2022
Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm
Critical9.8Oct 27, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.