Vulnerabilities
Vulnerable Software
Apache:  >> Storm  >> 0.9.0.1  Security Vulnerabilities
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.
CVSS Score
6.5
EPSS Score
0.004
Published
2018-06-05
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
CVSS Score
5.5
EPSS Score
0.153
Published
2018-06-05
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.
CVSS Score
7.5
EPSS Score
0.007
Published
2017-10-30


Contact Us

Shodan ® - All rights reserved