apache-stormGHSA-cpp8-r8pr-wv4v
Apache Storm log viewer path traversal vulnerability
High7.5CVE-2014-0115 · Published May 17, 2022 · updated Nov 8, 2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.storm:storm Maven | <= 0.9.0.1 | No fix yet |
Details and references
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a `..` (dot dot) in the file parameter to log.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2014-0115
More apache-storm advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 142022 | Apache Storm remote code execution vulnerability CVE-2015-3188Critical9.8fixed in 0.10.0-beta1 | Critical9.8 | 0.10.0-beta1 |
| Oct 272021 | Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm CVE-2021-40865Critical9.8fixed in 1.2.4, 2.1.1, 2.2.1 | Critical9.8 | 1.2.4, 2.1.1, 2.2.1 |
| Oct 272021 | Command injection leading to Remote Code Execution in Apache Storm CVE-2021-38294Critical9.8fixed in 1.2.4, 2.1.1, 2.2.1 | Critical9.8 | 1.2.4, 2.1.1, 2.2.1 |