Skip to content
stormGHSA-cg5h-q983-4rww

Apache Storm remote code execution vulnerability

Critical9.8CVE-2015-3188 · Published May 14, 2022 · updated Nov 8, 2023

The UI daemon in Apache Storm 0.10.0-beta allows remote users to run arbitrary code as the user running the web server. With kerberos authentication this could allow impersonation of arbitrary users on other systems, including HDFS and HBase.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.storm:storm
Maven
>= 0.10.0-beta, < 0.10.0-beta10.10.0-beta1
Details and references

More storm advisories

All storm
Advisory
Apache Storm log viewer path traversal vulnerability
High7.5May 17, 2022
Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm
Critical9.8Oct 27, 2021
Command injection leading to Remote Code Execution in Apache Storm
Critical9.8Oct 27, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.