Apache / Storm
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41081 | Apache Storm Client: Anonymous principal assigned on TLS client certificate verification failure | MEDIUM | 6.5 | Apr 27, 2026 |
| CVE-2026-35337 | Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling | HIGH | 8.8 | Apr 13, 2026 |
| CVE-2026-35565 | Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI | MEDIUM | 5.4 | Apr 13, 2026 |
| CVE-2023-43123 | Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files | MEDIUM | 5.5 | Nov 23, 2023 |
| CVE-2021-40865 | Unsafe Pre-Authentication Deserialization In Workers | CRITICAL | 9.8 | Oct 25, 2021 |
| CVE-2021-38294 | Shell Command Injection Vulnerability in Nimbus Thrift Server | CRITICAL | 9.8 | Oct 25, 2021 |
| CVE-2018-11779 | In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to d… | CRITICAL | 9.8 | Jul 25, 2019 |
| CVE-2019-0202 | The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating… | HIGH | 7.5 | Jul 25, 2019 |
| CVE-2018-1331 | In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in… | HIGH | 8.8 | Jul 10, 2018 |
| CVE-2018-8008 | Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved usi… | MEDIUM | 5.5 | Jun 5, 2018 |
| CVE-2018-1332 | Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another… | MEDIUM | 6.5 | Jun 5, 2018 |
| CVE-2014-0115 | Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file para… | HIGH | 7.5 | Oct 30, 2017 |
| CVE-2017-9799 | It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner… | HIGH | 8.8 | Aug 9, 2017 |
| CVE-2015-3188 | The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors. | CRITICAL | 9.8 | Jan 13, 2017 |
Showing 1 to 14 of 14 CVEs