Apache storm
This hub aggregates every CVE we track for Apache storm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
2
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM3HIGH2CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 7 most recently published vulnerabilities affecting Apache storm.
- CVE-2023-43123Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files5.5
- CVE-2021-40865Unsafe Pre-Authentication Deserialization In Workers9.8
- CVE-2021-38294Shell Command Injection Vulnerability in Nimbus Thrift Server9.8
- CVE-2018-1331In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary cod...8.8
- CVE-2018-8008Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (af...5.5
- CVE-2018-1332Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Stor...6.5
- CVE-2017-9799It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor ...8.8
Product normalization is registry-driven with AI assist and human review. How it works