GHSA-cg5h-q983-4rww
Dashboard / Vulnerabilities / GHSA-cg5h-q983-4rww
Summary: Apache Storm remote code execution vulnerability
Details: The UI daemon in Apache Storm 0.10.0-beta allows remote users to run arbitrary code as the user running the web server. With kerberos authentication this could allow impersonation of arbitrary users on other systems, including HDFS and HBase.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-3188, https://github.com/apache/storm/blob/v0.10.0-beta1/SECURITY.md, https://github.com/apache/storm/blob/v0.10.0-beta1/STORM-UI-REST-API.md, https://web.archive.org/web/20151014213052/http://www.securitytracker.com/id/1032695, https://web.archive.org/web/20171202122914/http://www.securityfocus.com/archive/1/535804/100/0/threaded, http://packetstormsecurity.com/files/132417/Apache-Storm-0.10.0-beta-Code-Execution.html
Affected packages
Package
Name: org.apache.storm:storm
Purl: pkg:maven/org.apache.storm/storm
Affected ranges
Type: ECOSYSTEM
Events:
