org.apache.storm:storm-core
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.storm:storm-corepage 1 of 1
- CVE-2017-9799HIGHCVSS 8.8EG 8.8✓ Fixed in 1.0.42017-08-09
vulnerable: 1.0.0, 1.0.1, 1.0.2, 1.0.3
It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-roo…
- CVE-2018-1331HIGHCVSS 8.8EG 8.8✓ Fixed in 1.1.32018-07-10
vulnerable: 0.10.0 ... 1.1.2 (22 versions)
In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.
- CVE-2018-1332MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.2.22018-06-05
vulnerable: 1.2.0, 1.2.1
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.
- CVE-2018-8008MEDIUMCVSS 5.5EG 5.5✓ Fixed in 1.0.72018-06-05
vulnerable: 0.10.0 ... 1.0.6 (19 versions)
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, …
- CVE-2019-0202HIGHCVSS 7.5EG 7.5✓ Fixed in 1.2.32019-07-26
vulnerable: 0.10.0 ... 1.2.2 (26 versions)
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not …
- CVE-2023-43123MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.6.02023-11-23
vulnerable: 2.0.0 ... 2.5.0 (8 versions)
On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not im…
Check whether org.apache.storm:storm-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.storm:storm-core CVEs against the assets you own.
Start Free Scan →