Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2023-43123

Apache Storm: storm-core temporary file readable by other local users

Technology

Apache Storm

CVSS Score

5.5 / 10.0

Affected Versions

Apache Storm 2.0.0 to before 2.6.0

Upstream Fix

2.6.0

Published

November 23, 2023

OSSeva Coverage

Fixed upstream

Description

TopologySpoutLag in storm-core writes a temporary file with File.createTempFile, which on Unix-like systems is readable by other local users. Apache describes the impact as very limited, because the class is used only when ui.disable.spout.lag.monitoring is set to false, which is not the default, and the file is deleted soon after it is created.

Upstream record: NVD · CVE.org

Is your Apache Storm deployment affected?

If you're running Apache Storm 2.0.0 to before 2.6.0, you need this patch. Book a discovery call to get covered.