CVE-2018-1331

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/07/2018
Last modified:
03/10/2019

Description

In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:* 0.10.0 (excluding) 0.10.2 (including)
cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:* 1.0.0 (including) 1.0.6 (including)
cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:* 1.1.0 (excluding) 1.1.2 (including)
cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:* 1.2.0 (including) 1.2.1 (including)