CVE-2021-40865
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE).
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 65.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 65.59% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- apache/storm
- Source
- security@apache.org
References
- https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.org%3EMailing List, Vendor Advisory
- https://seclists.org/oss-sec/2021/q4/45Mailing List, Third Party Advisory
- https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.org%3EMailing List, Vendor Advisory
- https://seclists.org/oss-sec/2021/q4/45Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.