9.8
CVSSv3

CVE-2021-40865

Published: 25/10/2021 Updated: 28/10/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache storm

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2021-40865: Apache Storm: Unsafe Pre-Authentication Deserialization In Workers <!--X-Subject-Header-End--> <!--X-Head-of-M ...

Github Repositories

CVE-2021-40865

CVE-2021-40865 CVE-2021-40865 POC/exploit-poc import orgapachecommonsioIOUtils; import orgapachestormserializationKryoValuesSerializer; import ysoserialpayloadsObjectPayload; import ysoserialpayloadsURLDNS; import javaio*; import javamathBigInteger; import javanet*; import javautilHashMap; public class NettyExploit { /** * Encoded as -600 sho