Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-96663
HistoryNov 27, 2023 - 12:00 a.m.

Apache Storm Information Disclosure Vulnerability (CNVD-2023-9666324)

2023-11-2700:00:00
China National Vulnerability Database
www.cnvd.org.cn
5
apache storm
information disclosure
vulnerability
temporary directory
shared
api
unspecified permissions
sensitive information

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Apache Storm is the United States Apache (Apache) Foundation of a set of open source distributed real-time computing system developed using Clojure (concurrent programming language). Apache Storm suffers from an information disclosure vulnerability that stems from a temporary directory shared among all users, which can be exploited by an attacker to write to the directory using an API with unspecified permissions, leading to the disclosure of sensitive information.

CPENameOperatorVersion
apache apache storm >=2.0.0,lt2.6.0

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%