Vulnerability Details CVE-2019-0202
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-0202
-
cpe:2.3:a:apache:storm:0.10.0
-
cpe:2.3:a:apache:storm:0.10.1
-
cpe:2.3:a:apache:storm:0.10.2
-
cpe:2.3:a:apache:storm:0.9.1
-
cpe:2.3:a:apache:storm:0.9.2
-
cpe:2.3:a:apache:storm:0.9.3
-
cpe:2.3:a:apache:storm:0.9.4
-
cpe:2.3:a:apache:storm:0.9.5
-
cpe:2.3:a:apache:storm:0.9.6
-
cpe:2.3:a:apache:storm:0.9.7
-
cpe:2.3:a:apache:storm:1.0
-
cpe:2.3:a:apache:storm:1.0.0
-
cpe:2.3:a:apache:storm:1.0.1
-
cpe:2.3:a:apache:storm:1.0.2
-
cpe:2.3:a:apache:storm:1.0.3
-
cpe:2.3:a:apache:storm:1.0.4
-
cpe:2.3:a:apache:storm:1.0.5
-
cpe:2.3:a:apache:storm:1.0.6
-
cpe:2.3:a:apache:storm:1.0.7
-
cpe:2.3:a:apache:storm:1.1
-
cpe:2.3:a:apache:storm:1.1.0
-
cpe:2.3:a:apache:storm:1.1.1
-
cpe:2.3:a:apache:storm:1.1.2
-
cpe:2.3:a:apache:storm:1.1.3
-
cpe:2.3:a:apache:storm:1.2.0
-
cpe:2.3:a:apache:storm:1.2.1
-
cpe:2.3:a:apache:storm:1.2.2