Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2021-40865

Apache Storm: pre-authentication deserialization in the supervisor's worker services

Technology

Apache Storm

CVSS Score

9.8 / 10.0

Affected Versions

Apache Storm 1.x before 1.2.4, 2.1.0, 2.2.0

Upstream Fix

1.2.4, 2.1.1, 2.2.1, 2.3.0

Published

October 25, 2021

OSSeva Coverage

Fixed upstream

Description

The worker services of the Storm supervisor deserialize untrusted data before authentication, so a remote attacker who can reach a worker port can run code. Apache's advisory tells 2.2.x users to upgrade to 2.2.1 or 2.3.0, 2.1.x users to 2.1.1 and 1.x users to 1.2.4.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 1.x before 1.2.4, 2.1.0, 2.2.0, you need this patch. Book a discovery call to get covered.