https://seclists.org/oss-sec/2021/q4/44
Published Oct 21, 2021
·Updated
Affected Software
2 affected components
Apache storm<2.2.1
Apache storm<1.2.4
Frequently Asked Questions
1
What is the severity of CVE-2021-36749?
The severity of CVE-2021-36749 is classified as high.
2
How do I fix CVE-2021-36749?
To fix CVE-2021-36749, upgrade Apache Storm to version 2.2.1 or later for the 2.x branch and to version 1.2.4 or later for the 1.x branch.
3
What is the impact of CVE-2021-36749?
The impact of CVE-2021-36749 is that it allows for Remote Code Execution (RCE) on the Nimbus server through a crafted thrift request.
4
Is authentication required to exploit CVE-2021-36749?
No, authentication is not required to exploit CVE-2021-36749.
5
Which versions of Apache Storm are affected by CVE-2021-36749?
CVE-2021-36749 affects Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4.