CVE-2018-1332: Infoleak
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Apache Storm vulnerability?
The vulnerability ID for this Apache Storm vulnerability is CVE-2018-1332.
What is the severity of CVE-2018-1332?
CVE-2018-1332 has a severity rating of medium.
Which versions of Apache Storm are affected?
Apache Storm versions 1.0.6 and earlier, 1.1.2 and earlier, and 1.2.1 and earlier are affected.
How can this vulnerability be exploited?
This vulnerability can be exploited to allow a user to impersonate another user when communicating with some Storm Daemons.
Where can I find more information about CVE-2018-1332?
You can find more information about CVE-2018-1332 at the following references: [http://www.securityfocus.com/bid/104399](http://www.securityfocus.com/bid/104399) and [https://lists.apache.org/thread.html/50f1d6a7af27f49d2e498a9ab2975685302cd8ca47000b7c38f339a4@%3Cdev.storm.apache.org%3E](https://lists.apache.org/thread.html/50f1d6a7af27f49d2e498a9ab2975685302cd8ca47000b7c38f339a4@%3Cdev.storm.apache.org%3E).