PT-2015-3343 · Apache · Apache Storm
Published
2015-06-22
·
Updated
2022-05-14
·
CVE-2015-3188
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Storm version 0.10.0
Description
The issue is related to the UI daemon in Apache Storm, which has insufficient access controls. This allows remote attackers to execute arbitrary code. With Kerberos authentication, this could potentially allow impersonation of arbitrary users on other systems, including HDFS and HBase.
Recommendations
For Apache Storm version 0.10.0, update to a version after 0.10.0-beta1 to resolve the issue. As a temporary workaround, consider restricting access to the UI daemon to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Storm