Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2023-43123
Apache Storm: storm-core temporary file readable by other local users
Technology
Apache Storm
CVSS Score
5.5 / 10.0
Affected Versions
Apache Storm 2.0.0 to before 2.6.0
Upstream Fix
2.6.0
Published
November 23, 2023
OSSeva Coverage
Fixed upstream
Description
TopologySpoutLag in storm-core writes a temporary file with File.createTempFile, which on Unix-like systems is readable by other local users. Apache describes the impact as very limited, because the class is used only when ui.disable.spout.lag.monitoring is set to false, which is not the default, and the file is deleted soon after it is created.
Is your Apache Storm deployment affected?
If you're running Apache Storm 2.0.0 to before 2.6.0, you need this patch. Book a discovery call to get covered.