PT-2015-3343 · Apache · Apache Storm

Publicado

2015-06-22

·

Atualizado

2022-05-14

·

CVE-2015-3188

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Storm version 0.10.0
Description The issue is related to the UI daemon in Apache Storm, which has insufficient access controls. This allows remote attackers to execute arbitrary code. With Kerberos authentication, this could potentially allow impersonation of arbitrary users on other systems, including HDFS and HBase.
Recommendations For Apache Storm version 0.10.0, update to a version after 0.10.0-beta1 to resolve the issue. As a temporary workaround, consider restricting access to the UI daemon to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02543
CVE-2015-3188
GHSA-CG5H-Q983-4RWW

Produtos afetados

Apache Storm