Skip to content
apache-stormGHSA-cpp8-r8pr-wv4v

Apache Storm log viewer path traversal vulnerability

High7.5CVE-2014-0115 · Published May 17, 2022 · updated Nov 8, 2023

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.storm:storm
Maven
<= 0.9.0.1No fix yet
Details and references

Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a `..` (dot dot) in the file parameter to log.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2014-0115

More apache-storm advisories

All
DateAdvisory
May 142022Apache Storm remote code execution vulnerability
CVE-2015-3188Critical9.8fixed in 0.10.0-beta1
Oct 272021Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm
CVE-2021-40865Critical9.8fixed in 1.2.4, 2.1.1, 2.2.1
Oct 272021Command injection leading to Remote Code Execution in Apache Storm
CVE-2021-38294Critical9.8fixed in 1.2.4, 2.1.1, 2.2.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.