Information disclosure in Apache Storm - CVE-2017-9799
Published: August 15, 2017
Vulnerability identifier: #VU7887
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9799
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information on the target system.
The weakness exists due to improper access controls. A remote authenticated user that is the owner of a topology can exploit a flaw to cause the supervisor to launch a worker as a different (non-root) user and obtain credentials from the target user account.
Successful exploitation of the vulnerability results in information disclosure.
The weakness exists due to improper access controls. A remote authenticated user that is the owner of a topology can exploit a flaw to cause the supervisor to launch a worker as a different (non-root) user and obtain credentials from the target user account.
Successful exploitation of the vulnerability results in information disclosure.
Affected software
Apache Storm
SUSE OpenStack Cloud
SUSE OpenStack Cloud
How to mitigate CVE-2017-9799
Update to version 1.0.4 or 1.1.1.