CVE-2014-0115: Path Traversal
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.
Other sources
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0115?
CVE-2014-0115 is classified as a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2014-0115?
To fix CVE-2014-0115, upgrade to a patched version of Apache Storm that addresses the directory traversal vulnerability.
What type of vulnerability is CVE-2014-0115?
CVE-2014-0115 is a directory traversal vulnerability that allows attackers to read arbitrary files from the system.
Which versions of Apache Storm are affected by CVE-2014-0115?
CVE-2014-0115 specifically affects Apache Storm version 0.9.0.1.
Can CVE-2014-0115 be exploited remotely?
Yes, CVE-2014-0115 can be exploited remotely by attackers using crafted input.