Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20890
HistoryJul 25, 2019 - 7:11 a.m.

Deserialization Of Untrusted Object

2019-07-2507:11:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3

0.003 Low

EPSS

Percentile

69.0%

Apache Storm UI Deamon is vulnerable to deserialization of untrusted object. When it is using with storm-kafka-client or storm-kafka modules, it does not filter the input of untrusted bytes before deserialization, allowing an attacker to provide malicious bytes to abuse the logic of the application.

CPENameOperatorVersion
storm corele1.2.2

0.003 Low

EPSS

Percentile

69.0%

Related for VERACODE:20890