QID 981207

QID 981207: Java (maven) Security Update for org.apache.storm:storm-core (GHSA-898j-5cc8-cmf5)

Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to refer to GHSA-898j-5cc8-cmf5 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981207

    Software Advisories
    Advisory ID Software Component Link
    GHSA-898j-5cc8-cmf5 org.apache.storm:storm-core URL Logo github.com/advisories/GHSA-898j-5cc8-cmf5