7.5
CVSSv2

CVE-2021-38294

Published: 25/10/2021 Updated: 18/10/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 670
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x before 2.2.1 and Apache Storm 1.x before 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache storm

Mailing Lists

Severity: high Description: A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2x prior to 221 and Apache Storm 1x prior to 124 A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication Mitigation: Apache Storm 22x users should upgr ...