PT-2015-3343 · Apache · Apache Storm

Published

2015-06-22

·

Updated

2022-05-14

·

CVE-2015-3188

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Storm version 0.10.0
Description The issue is related to the UI daemon in Apache Storm, which has insufficient access controls. This allows remote attackers to execute arbitrary code. With Kerberos authentication, this could potentially allow impersonation of arbitrary users on other systems, including HDFS and HBase.
Recommendations For Apache Storm version 0.10.0, update to a version after 0.10.0-beta1 to resolve the issue. As a temporary workaround, consider restricting access to the UI daemon to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02543
CVE-2015-3188
GHSA-CG5H-Q983-4RWW

Affected Products

Apache Storm