First published: Thu Jul 25 2019(Updated: )
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Storm | >=0.9.3<=1.2.2 | |
Apache Storm | =0.9.1-incubating | |
Apache Storm | =0.9.2-incubating |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0202 is a vulnerability in Apache Storm Logviewer daemon that allows unauthorized access to files on the host's file system.
CVE-2019-0202 affects Apache Storm versions 0.9.1-incubating to 1.2.2.
CVE-2019-0202 has a severity rating of 7.5 (high).
An attacker can exploit CVE-2019-0202 by leveraging the exposed HTTP-accessible endpoints of the Logviewer daemon to read/search log files on the host system, including files not intended to be accessible.
To fix CVE-2019-0202, it is recommended to upgrade Apache Storm to a version later than 1.2.2 or apply the necessary patches provided by Apache.