Known vulnerabilities in Apache Storm

Software: Apache Storm
Software CPE: cpe:2.3:a:apache_foundation:apache_storm:*:*:*:*:*:*:*:*
Total vulnerabilities: 6
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Storm Apache Storm is affected by 6 known vulnerabilities: 3 high, 3 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83602 - Insecure Temporary File
CVE-2023-43123
CWE-377 Low
No
No
2.6.0 30.11.2023 SB2023113048
#VU58269 - Deserialization of Untrusted Data
CVE-2021-40865
CWE-502 High
Available
No
1.2.4, 2.2.1 20.11.2021 SB2021112001
SB2022041519
SB2021110424
#VU58268 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-38294
CWE-78 High
Available
No
1.2.4, 2.2.1 20.11.2021 SB2021112001
SB2022041519
SB2021110424
#VU13796 - Permissions, Privileges, and Access Controls
CVE-2018-1331
CWE-264 High
No
No
1.1.3, 1.2.2 11.07.2018 SB2018071103
#VU13540 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-8008
CWE-22 Low
No
No
1.1.3, 1.2.2 25.06.2018 SB2018070207
#VU7887 - Exposure of sensitive information to an unauthorized actor
CVE-2017-9799
CWE-200 Low
No
No
- 15.08.2017 SB2017080901
SB2017111302
SB2017111303