Lucene search

K
cvelistApacheCVELIST:CVE-2019-0202
HistoryJul 25, 2019 - 11:17 p.m.

CVE-2019-0202

2019-07-2523:17:23
CWE-200
apache
www.cve.org

0.001 Low

EPSS

Percentile

30.0%

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host’s file system that were not intended to be accessible via these endpoints.

CNA Affected

[
  {
    "product": "Storm",
    "vendor": "Apache",
    "versions": [
      {
        "status": "affected",
        "version": "0.9.1-incubating to 1.2.2"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

30.0%

Related for CVELIST:CVE-2019-0202