Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2021-40865
Apache Storm: pre-authentication deserialization in the supervisor's worker services
Technology
Apache Storm
CVSS Score
9.8 / 10.0
Affected Versions
Apache Storm 1.x before 1.2.4, 2.1.0, 2.2.0
Upstream Fix
1.2.4, 2.1.1, 2.2.1, 2.3.0
Published
October 25, 2021
OSSeva Coverage
Fixed upstream
Description
The worker services of the Storm supervisor deserialize untrusted data before authentication, so a remote attacker who can reach a worker port can run code. Apache's advisory tells 2.2.x users to upgrade to 2.2.1 or 2.3.0, 2.1.x users to 2.1.1 and 1.x users to 1.2.4.
Is your Apache Storm deployment affected?
If you're running Apache Storm 1.x before 1.2.4, 2.1.0, 2.2.0, you need this patch. Book a discovery call to get covered.