Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2021-38294

Apache Storm: command injection in the Nimbus getTopologyHistory service

Technology

Apache Storm

CVSS Score

9.8 / 10.0

Affected Versions

Apache Storm 1.x before 1.2.4, 2.x before 2.2.1

Upstream Fix

1.2.4, 2.1.1, 2.2.1, 2.3.0

Published

October 25, 2021

OSSeva Coverage

Fixed upstream

Description

A crafted Thrift request to the getTopologyHistory service on Nimbus injects shell commands, giving remote code execution before authentication.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 1.x before 1.2.4, 2.x before 2.2.1, you need this patch. Book a discovery call to get covered.