CVE-2021-38294: Shell Command Injection Vulnerability in Nimbus Thrift Server
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-38294?
CVE-2021-38294 is a Command Injection vulnerability in the getTopologyHistory service of Apache Storm.
What is the severity of CVE-2021-38294?
CVE-2021-38294 has a severity rating of 9.8 (Critical).
Which versions of Apache Storm are affected by CVE-2021-38294?
CVE-2021-38294 affects Apache Storm 1.x prior to 1.2.4 and Apache Storm 2.x prior to 2.2.1.
How can CVE-2021-38294 be exploited?
CVE-2021-38294 can be exploited by sending a specially crafted thrift request to the Nimbus server, allowing Remote Code Execution (RCE) prior to authentication.
Is there a fix available for CVE-2021-38294?
Yes, upgrading to Apache Storm versions 2.2.1 or 1.2.4 resolves CVE-2021-38294.