QID 980020

QID 980020: Java (maven) Security Update for org.apache.storm:storm (GHSA-6768-mcjc-8223)

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-6768-mcjc-8223 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980020

    Software Advisories
    Advisory ID Software Component Link
    GHSA-6768-mcjc-8223 org.apache.storm:storm URL Logo github.com/advisories/GHSA-6768-mcjc-8223