stormGHSA-cg5h-q983-4rww
Apache Storm remote code execution vulnerability
Critical9.8CVE-2015-3188 · Published May 14, 2022 · updated Nov 8, 2023
The UI daemon in Apache Storm 0.10.0-beta allows remote users to run arbitrary code as the user running the web server. With kerberos authentication this could allow impersonation of arbitrary users on other systems, including HDFS and HBase.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.storm:storm Maven | >= 0.10.0-beta, < 0.10.0-beta1 | 0.10.0-beta1 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Also known as
- CVE-2015-3188
- nvd.nist.gov/vuln/detail/CVE-2015-3188
- github.com/apache/storm/blob/v0.10.0-beta1/SECURITY.md
- github.com/apache/storm/blob/v0.10.0-beta1/STORM-UI-REST-API.md
- web.archive.org/web/20151014213052/http://www.securitytracker.com/id/1032695
- web.archive.org/web/20171202122914/http://www.securityfocus.com/archive/1/535804/100/0/threaded
- packetstormsecurity.com/files/132417/Apache-Storm-0.10.0-beta-Code-Execution.html
More storm advisories
All storm| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Apache Storm log viewer path traversal vulnerability | High7.5 | No fix yet |
| Oct 272021 | Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm | Critical9.8 | 1.2.4+2 more |
| Oct 272021 | Command injection leading to Remote Code Execution in Apache Storm | Critical9.8 | 1.2.4+2 more |