Command injection leading to Remote Code Execution in Apache Storm
Critical severity
GitHub Reviewed
Published
Oct 27, 2021
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Package
Affected versions
>= 2.2.0, < 2.2.1
>= 2.0.0, < 2.1.1
>= 1.0.0, < 1.2.4
Patched versions
2.2.1
2.1.1
1.2.4
Description
Published by the National Vulnerability Database
Oct 25, 2021
Reviewed
Oct 26, 2021
Published to the GitHub Advisory Database
Oct 27, 2021
Last updated
Jan 31, 2023
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.
References