CVE-2021-38294

CRITICAL9.8EPSS 82.1%

Command injection leading to Remote Code Execution in Apache Storm

Published: 10/27/2021Modified: 11/8/2023
Also known as:GHSA-6768-mcjc-8223

Description

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (5)