PT-2019-11187 · Apache · Apache Storm
Published
2019-07-25
·
Updated
2022-05-24
·
CVE-2019-0202
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache Storm versions 0.9.1-incubating through 1.2.2
Description:
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read and search log files on hosts running Storm. This allows unauthorized access to read files off the host's file system that were not intended to be accessible via these endpoints.
Recommendations:
For Apache Storm versions 0.9.1-incubating through 1.2.2, consider restricting access to the Logviewer daemon to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Storm