Lucene search

K
osvGoogleOSV:GHSA-W729-7633-2FW5
HistoryOct 27, 2021 - 6:52 p.m.

Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm

2021-10-2718:52:06
Google
osv.dev
10

0.015 Low

EPSS

Percentile

86.8%

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4