QID 994764
Date Published: 2023-08-10
QID 994764: Java (Maven) Security Update for org.apache.storm:storm (GHSA-cg5h-q983-4rww)
The UI daemon in Apache Storm 0.10.0-beta allows remote users to run arbitrary code as the user running the web server. With kerberos authentication this could allow impersonation of arbitrary users on other systems, including HDFS and HBase.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-cg5h-q983-4rww for updates and patch information.
Vendor References
- GHSA-cg5h-q983-4rww -
github.com/advisories/GHSA-cg5h-q983-4rww
CVEs related to QID 994764
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cg5h-q983-4rww | org.apache.storm:storm |
|