GHSA-w729-7633-2fw5
Dashboard / Vulnerabilities / GHSA-w729-7633-2fw5
Summary: Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm
Details: An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4
References: https://nvd.nist.gov/vuln/detail/CVE-2021-40865, https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.org%3E, https://seclists.org/oss-sec/2021/q4/45
Affected packages
Package
Name: org.apache.storm:storm
Purl: pkg:maven/org.apache.storm/storm
Affected ranges
Type: ECOSYSTEM
Events:
