CVE-2014-0115

HIGH7.5EPSS 0.77%

Apache Storm log viewer path traversal vulnerability

Published: 5/17/2022Modified: 11/8/2023

Description

Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a `..` (dot dot) in the file parameter to log.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (3)