CVE-2021-40865: Unsafe Pre-Authentication Deserialization In Workers
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40865?
CVE-2021-40865 is an Unsafe Deserialization vulnerability in the worker services of the Apache Storm supervisor server, allowing pre-auth Remote Code Execution (RCE).
What is the severity of CVE-2021-40865?
CVE-2021-40865 has a severity rating of 9.8 (Critical).
Which versions of Apache Storm are affected by CVE-2021-40865?
Apache Storm 1.x versions up to 1.2.4, Apache Storm 2.1.x versions up to 2.1.1, and Apache Storm 2.2.x versions up to 2.2.1 are affected by CVE-2021-40865.
How can I fix CVE-2021-40865?
To fix CVE-2021-40865, Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0, Apache Storm 2.1.x users should upgrade to version 2.1.1, and Apache Storm 1.x users should upgrade to a version higher than 1.2.4.
Where can I find more information about CVE-2021-40865?
You can find more information about CVE-2021-40865 at the following references: [Link 1](https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.org%3E), [Link 2](https://seclists.org/oss-sec/2021/q4/45).