First published: Mon Oct 25 2021(Updated: )
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Storm | >=1.0.0<1.2.4 | |
Apache Storm | >=2.1.0<2.1.1 | |
Apache Storm | >=2.2.0<2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40865 is an Unsafe Deserialization vulnerability in the worker services of the Apache Storm supervisor server, allowing pre-auth Remote Code Execution (RCE).
CVE-2021-40865 has a severity rating of 9.8 (Critical).
Apache Storm 1.x versions up to 1.2.4, Apache Storm 2.1.x versions up to 2.1.1, and Apache Storm 2.2.x versions up to 2.2.1 are affected by CVE-2021-40865.
To fix CVE-2021-40865, Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0, Apache Storm 2.1.x users should upgrade to version 2.1.1, and Apache Storm 1.x users should upgrade to a version higher than 1.2.4.
You can find more information about CVE-2021-40865 at the following references: [Link 1](https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.org%3E), [Link 2](https://seclists.org/oss-sec/2021/q4/45).