CVE Database
/

CVE-2018-1331

Back to search

CVE-2018-1331

Published: Jul 10, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.

VendorProductVersions

Apache Software Foundation

Apache Storm

affected
0.10.0 through 0.10.2
affected
1.0.0 through 1.0.6
affected
1.1.0 through 1.1.2
affected
1.2.0 through 1.2.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now