Skip to content
stormGHSA-w729-7633-2fw5

Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm

Critical9.8CVE-2021-40865 · Published Oct 27, 2021 · updated Nov 8, 2023

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.storm:storm
Maven
>= 2.2.0, < 2.2.12.2.1
>= 1.0.0, < 1.2.41.2.4
>= 2.1.0, < 2.1.12.1.1
Details and references

More storm advisories

All storm
Advisory
Apache Storm log viewer path traversal vulnerability
High7.5May 17, 2022
Apache Storm remote code execution vulnerability
Critical9.8May 14, 2022
Command injection leading to Remote Code Execution in Apache Storm
Critical9.8Oct 27, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.