Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-11779

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-11779
  • Apache » Storm » Version: 1.1.0
    cpe:2.3:a:apache:storm:1.1.0
  • Apache » Storm » Version: 1.1.1
    cpe:2.3:a:apache:storm:1.1.1
  • Apache » Storm » Version: 1.1.2
    cpe:2.3:a:apache:storm:1.1.2
  • Apache » Storm » Version: 1.1.3
    cpe:2.3:a:apache:storm:1.1.3
  • Apache » Storm » Version: 1.2.0
    cpe:2.3:a:apache:storm:1.2.0
  • Apache » Storm » Version: 1.2.1
    cpe:2.3:a:apache:storm:1.2.1
  • Apache » Storm » Version: 1.2.2
    cpe:2.3:a:apache:storm:1.2.2


Contact Us

Shodan ® - All rights reserved