Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-40865
HistoryOct 25, 2021 - 1:15 p.m.

Deserialization of untrusted data

2021-10-2513:15:00
PRIOn knowledge base
www.prio-n.com
6

9.6 High

AI Score

Confidence

High

0.015 Low

EPSS

Percentile

86.8%

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4

9.6 High

AI Score

Confidence

High

0.015 Low

EPSS

Percentile

86.8%