Lucene search

K
osvGoogleOSV:GHSA-CG5H-Q983-4RWW
HistoryMay 14, 2022 - 2:48 a.m.

Apache Storm remote code execution vulnerability

2022-05-1402:48:54
Google
osv.dev
3

0.02 Low

EPSS

Percentile

88.8%

The UI daemon in Apache Storm 0.10.0-beta allows remote users to run arbitrary code as the user running the web server. With kerberos authentication this could allow impersonation of arbitrary users on other systems, including HDFS and HBase.

CPENameOperatorVersion
org.apache.storm:stormeq0.10.0-beta

0.02 Low

EPSS

Percentile

88.8%

Related for OSV:GHSA-CG5H-Q983-4RWW