https://seclists.org/oss-sec/2021/q4/45
Published Oct 21, 2021
·Updated
Affected Software
3 affected components
Apache storm<2.2.1, >=2.2.1<2.3.0
Apache storm<2.1.1
Apache storm<1.2.4
Frequently Asked Questions
1
What is the severity of CVE-2021-22910?
The severity of CVE-2021-22910 is classified as high.
2
What type of vulnerability is CVE-2021-22910?
CVE-2021-22910 is an Unsafe Deserialization vulnerability that allows pre-auth Remote Code Execution (RCE).
3
How do I fix CVE-2021-22910?
To fix CVE-2021-22910, users of Apache Storm 2.2.x should upgrade to version 2.2.1 or 2.3.0.
4
Which versions of Apache Storm are affected by CVE-2021-22910?
Apache Storm versions 2.2.x and 2.1.x are affected by CVE-2021-22910.
5
When was CVE-2021-22910 published?
CVE-2021-22910 was published on October 21, 2021.