QID 981207
QID 981207: Java (maven) Security Update for org.apache.storm:storm-core (GHSA-898j-5cc8-cmf5)
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-898j-5cc8-cmf5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-898j-5cc8-cmf5 -
github.com/advisories/GHSA-898j-5cc8-cmf5
CVEs related to QID 981207
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-898j-5cc8-cmf5 | org.apache.storm:storm-core |
|