QID 730267

Date Published: 2021-11-30

QID 730267: Apache Storm Multiple Vulnerabilities

Apache Storm is a free and open source distributed real-time computation system. Storm makes it easy to reliably process unbounded streams of data, doing for realtime processing what Hadoop did for batch processing.

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE).
Apache Storm: Shell Command Injection Vulnerability in Nimbus Thrift Server

Affected Versions:
Apache Storm 2.2.x up to to version version 2.2.0
Apache Storm 2.1.x up to to version 2.1.0
Apache Storm 1.x up to to version 1.2.3

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Apache Storm.

The attacker can perform a pre-auth Remote Code Execution (RCE).

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released patch.
    For more information please visit CVE-2021-40865 , CVE-2021-38294

    CVEs related to QID 730267

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-38294 URL Logo lists.apache.org/thread/ncwxn6s18pmrbklryjg7kxn3qx4wjtqr
    CVE-2021-40865 URL Logo lists.apache.org/thread/wt9f7lsz6xhyxotf0g099w3xbs9f1b1x