PT-2019-11187 · Apache · Apache Storm

Published

2019-07-25

·

Updated

2022-05-24

·

CVE-2019-0202

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache Storm versions 0.9.1-incubating through 1.2.2
Description: The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read and search log files on hosts running Storm. This allows unauthorized access to read files off the host's file system that were not intended to be accessible via these endpoints.
Recommendations: For Apache Storm versions 0.9.1-incubating through 1.2.2, consider restricting access to the Logviewer daemon to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-0202
GHSA-R9PV-HG64-JQRP
SUSE-SU-2020:2876-1
SUSE-SU-2020:3309-1

Affected Products

Apache Storm