Known vulnerabilities in Apache Storm
Vendor:
Apache Foundation
Software:
Apache Storm
Software CPE:
cpe:2.3:a:apache_foundation:apache_storm:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
6
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
3.0.0
2.8.9
2.8.8
2.8.7
2.8.6
2.8.5
2.8.4
2.8.3
2.8.2
2.8.1
2.8.0
2.7.1
2.7.0
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
2.5.0
2.4.0
2.3.0
2.2.1
2.2.0
2.1.1
2.1.0
2.0.0
1.2.4
1.2.3
0.9.7
0.9.0
0.8.2
0.8.1
1.2.0
1.0.5
1.0.3
1.0.2
1.0.1
0.10.2
0.10.1
1.0.6
1.1.2
1.2.1
1.1.3
1.2.2
1.1.1
1.0.4
0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6
0.10.0
1.0.0
1.1.0
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83602 - Insecure Temporary File CVE-2023-43123 |
CWE-377 | Low | 2.6.0 | 30.11.2023 |
SB2023113048 |
||
| #VU58269 - Deserialization of Untrusted Data CVE-2021-40865 |
CWE-502 | High | 1.2.4, 2.2.1 | 20.11.2021 |
SB2021112001 SB2022041519 SB2021110424 |
||
| #VU58268 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-38294 |
CWE-78 | High | 1.2.4, 2.2.1 | 20.11.2021 |
SB2021112001 SB2022041519 SB2021110424 |
||
| #VU13796 - Permissions, Privileges, and Access Controls CVE-2018-1331 |
CWE-264 | High | 1.1.3, 1.2.2 | 11.07.2018 |
SB2018071103 |
||
| #VU13540 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2018-8008 |
CWE-22 | Low | 1.1.3, 1.2.2 | 25.06.2018 |
SB2018070207 |
||
| #VU7887 - Exposure of sensitive information to an unauthorized actor CVE-2017-9799 |
CWE-200 | Low | - | 15.08.2017 |
SB2017080901 SB2017111302 SB2017111303 |