Lucene search

K
osvGoogleOSV:GHSA-25PC-85QF-6J69
HistoryAug 01, 2019 - 7:17 p.m.

Deserialization of Untrusted Data in Apache Storm

2019-08-0119:17:53
Google
osv.dev
8

0.003 Low

EPSS

Percentile

69.0%

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.

0.003 Low

EPSS

Percentile

69.0%

Related for OSV:GHSA-25PC-85QF-6J69