Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x825-rjww-2245

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Apache Storm it is possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user

It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised.

Пакеты

Наименование

org.apache.storm:storm-core

maven
Затронутые версииВерсия исправления

= 1.1.0

1.1.1

Наименование

org.apache.storm:storm-core

maven
Затронутые версииВерсия исправления

>= 1.0.0, < 1.0.4

1.0.4

EPSS

Процентиль: 75%
0.00887
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 8 лет назад

It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised.

EPSS

Процентиль: 75%
0.00887
Низкий

8.8 High

CVSS3