QID 730267
Date Published: 2021-11-30
QID 730267: Apache Storm Multiple Vulnerabilities
Apache Storm is a free and open source distributed real-time computation system. Storm makes it easy to reliably process unbounded streams of data, doing for realtime processing what Hadoop did for batch processing.
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE).
Apache Storm: Shell Command Injection Vulnerability in Nimbus Thrift Server
Affected Versions:
Apache Storm 2.2.x up to to version version 2.2.0
Apache Storm 2.1.x up to to version 2.1.0
Apache Storm 1.x up to to version 1.2.3
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Apache Storm.
The attacker can perform a pre-auth Remote Code Execution (RCE).
- CVE-2021-38294 -
lists.apache.org/thread/ncwxn6s18pmrbklryjg7kxn3qx4wjtqr - CVE-2021-40865 -
lists.apache.org/thread/wt9f7lsz6xhyxotf0g099w3xbs9f1b1x
CVEs related to QID 730267
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-38294 |
|
||
| CVE-2021-40865 |
|