PT-2021-5490 · Apache · Apache Storm

Alvaro Muñoz

+1

·

Published

2021-10-25

·

Updated

2021-11-28

·

CVE-2021-40865

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Storm versions 2.2.x prior to 2.2.1 Apache Storm versions 2.1.x prior to 2.1.1 Apache Storm versions 1.x prior to 1.2.4
Description An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server, allowing pre-auth Remote Code Execution (RCE). This vulnerability can be exploited by a remote attacker to execute arbitrary code in the target system.
Recommendations For Apache Storm versions 2.2.x, upgrade to version 2.2.1 or 2.3.0. For Apache Storm versions 2.1.x, upgrade to version 2.1.1. For Apache Storm versions 1.x, upgrade to version 1.2.4.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06339
CVE-2021-40865
GHSA-W729-7633-2FW5
OESA-2021-1415

Affected Products

Apache Storm