QID 980798
QID 980798: Java (maven) Security Update for org.apache.storm:storm-core (GHSA-x825-rjww-2245)
It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x825-rjww-2245 for updates pertaining to this vulnerability.
Vendor References
- GHSA-x825-rjww-2245 -
github.com/advisories/GHSA-x825-rjww-2245
CVEs related to QID 980798
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x825-rjww-2245 | org.apache.storm:storm-core |
|