In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/3e4f704c4bd9296405a07a0290b8cbb6cbf5046e277efe6d93280a98@%3Cuser.storm.apache.org%3E | Mailing List Vendor Advisory |
Configurations
Information
Published : 2019-07-25 17:15
Updated : 2019-10-09 16:33
NVD link : CVE-2018-11779
Mitre link : CVE-2018-11779
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
apache
- storm