Org.apache.storm:storm
This hub aggregates every CVE we track for Org.apache.storm:storm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
3
Critical
1
High
0
In CISA KEV
Severity distribution
CRITICAL3HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 4 most recently published vulnerabilities affecting Org.apache.storm:storm.
- CVE-2021-40865Unsafe Pre-Authentication Deserialization In Workers9.8
- CVE-2021-38294Shell Command Injection Vulnerability in Nimbus Thrift Server9.8
- CVE-2014-0115Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.7.5
- CVE-2015-3188The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.9.8
Product normalization is registry-driven with AI assist and human review. How it works