Apache
Apache Storm: vulnerabilidades y CVE
Apache Storm tiene 29 vulnerabilidades publicadas, 18 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses18
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82438 | Alta (8.1) | 0.21% | — | 14 sept 2026 | Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back… |
| CVE-2026-82437 | Media (4.3) | 0.28% | — | 14 sept 2026 | Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemon logs those settings were not applied: the access decision combined the "this is a daemon log"… |
| CVE-2026-82435 | Crítica (9.8) | 0.65% | — | 14 sept 2026 | Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a… |
| CVE-2026-82434 | Crítica (10) | 0.50% | — | 14 sept 2026 | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration… |
| CVE-2026-82433 | Media (6.5) | 0.34% | — | 14 sept 2026 | Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes… |
| CVE-2026-82432 | Alta (8.1) | 0.37% | — | 14 sept 2026 | Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never… |
| CVE-2026-82431 | Crítica (9.8) | 0.39% | — | 14 sept 2026 | Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone,… |
| CVE-2026-82430 | Alta (7.8) | 0.14% | — | 14 sept 2026 | Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the… |
| CVE-2026-82429 | Alta (7.8) | 0.13% | — | 14 sept 2026 | Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with… |
| CVE-2026-82428 | Alta (8.8) | 0.69% | — | 14 sept 2026 | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the… |
| CVE-2026-82427 | Alta (7.8) | 0.15% | — | 14 sept 2026 | Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without… |
| CVE-2026-82426 | Media (6.5) | 0.42% | — | 14 sept 2026 | Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had… |
| CVE-2026-84179 | Media (6.5) | 0.43% | — | 14 sept 2026 | Description |
| CVE-2026-82441 | Crítica (9.1) | 0.27% | — | 14 sept 2026 | Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of… |
| CVE-2026-82439 | Crítica (9.8) | 0.34% | — | 14 sept 2026 | Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its… |
| CVE-2026-41081 | Media (6.5) | 0.45% | — | 27 abr 2026 | Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without… |
| CVE-2026-35565 | Media (5.4) | 0.59% | — | 13 abr 2026 | Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component… |
| CVE-2026-35337 | Alta (8.8) | 1.1% | — | 13 abr 2026 | Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the… |
| CVE-2023-43123 | Media (5.5) | 0.35% | — | 23 nov 2023 | On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of… |
| CVE-2021-40865 | Crítica (9.8) | 64% | — | 25 oct 2021 | An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or… |
| CVE-2021-38294 | Crítica (9.8) | 84% | — | 25 oct 2021 | A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows… |
| CVE-2019-0202 | Alta (7.5) | 2.0% | — | 26 jul 2019 | The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file… |
| CVE-2018-11779 | Crítica (9.8) | 3.5% | — | 26 jul 2019 | In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class. |
| CVE-2018-1331 | Alta (8.8) | 4.4% | — | 10 jul 2018 | In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user. |
| CVE-2018-8008 | Media (5.5) | 2.3% | — | 5 jun 2018 | Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives… |
| CVE-2018-1332 | Media (6.5) | 1.5% | — | 5 jun 2018 | Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons. |
| CVE-2014-0115 | Alta (7.5) | 5.3% | — | 30 oct 2017 | Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log. |
| CVE-2017-9799 | Alta (8.8) | 4.9% | — | 9 ago 2017 | It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as… |
| CVE-2015-3188 | Crítica (9.8) | 14% | — | 13 ene 2017 | The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.