Vulnerability Details CVE-2018-11779
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.0%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-11779
-
cpe:2.3:a:apache:storm:1.1.0
-
cpe:2.3:a:apache:storm:1.1.1
-
cpe:2.3:a:apache:storm:1.1.2
-
cpe:2.3:a:apache:storm:1.1.3
-
cpe:2.3:a:apache:storm:1.2.0
-
cpe:2.3:a:apache:storm:1.2.1
-
cpe:2.3:a:apache:storm:1.2.2