First published: Mon Oct 25 2021(Updated: )
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Storm | >=1.0.0<1.2.4 | |
Apache Storm | >=2.1.0<2.1.1 | |
Apache Storm | >=2.2.0<2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38294 is a Command Injection vulnerability in the getTopologyHistory service of Apache Storm.
CVE-2021-38294 has a severity rating of 9.8 (Critical).
CVE-2021-38294 affects Apache Storm 1.x prior to 1.2.4 and Apache Storm 2.x prior to 2.2.1.
CVE-2021-38294 can be exploited by sending a specially crafted thrift request to the Nimbus server, allowing Remote Code Execution (RCE) prior to authentication.
Yes, upgrading to Apache Storm versions 2.2.1 or 1.2.4 resolves CVE-2021-38294.