Lucene search

K
osvGoogleOSV:CVE-2019-0202
HistoryJul 26, 2019 - 12:15 a.m.

CVE-2019-0202

2019-07-2600:15:11
Google
osv.dev
4

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

30.0%

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host’s file system that were not intended to be accessible via these endpoints.

CPENameOperatorVersion
stormeq0.9.3

6.7 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

30.0%