CVE-2018-11779: Critical severity apache storm vulnerability
Published Jul 25, 2019
·Updated
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
Affected Software
1 affected component
Apache storm>=1.1.0<=1.2.2
Event History
Jul 25, 2019
CVE Published
via MITRE·11:23 PM
Data Sourced
via MITRE·11:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-11779?
CVE-2018-11779 is a vulnerability in Apache Storm versions 1.1.0 to 1.2.2 that allows the deserialization of user provided bytes into a Java class.
2
How severe is CVE-2018-11779?
CVE-2018-11779 has a severity rating of 9.8, which is considered critical.
3
Which software is affected by CVE-2018-11779?
Apache Storm versions 1.1.0 to 1.2.2 are affected by CVE-2018-11779.
4
What is the Common Weakness Enumeration (CWE) for CVE-2018-11779?
The CWE for CVE-2018-11779 is CWE-502, which is titled 'Deserialization of Untrusted Data.'
5
Is there a fix available for CVE-2018-11779?
Yes, there is a fix available for CVE-2018-11779. It is recommended to upgrade to a version of Apache Storm that is not affected by this vulnerability.