stormGHSA-w729-7633-2fw5
Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm
Critical9.8CVE-2021-40865 · Published Oct 27, 2021 · updated Nov 8, 2023
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.storm:storm Maven | >= 2.2.0, < 2.2.1 | 2.2.1 |
| >= 1.0.0, < 1.2.4 | 1.2.4 | |
| >= 2.1.0, < 2.1.1 | 2.1.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- CVE-2021-40865
More storm advisories
All storm| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 172022 | Apache Storm log viewer path traversal vulnerability | High7.5 | No fix yet |
| May 142022 | Apache Storm remote code execution vulnerability | Critical9.8 | 0.10.0-beta1 |
| Oct 272021 | Command injection leading to Remote Code Execution in Apache Storm | Critical9.8 | 1.2.4+2 more |