CVE Database
/

CVE-2021-38294

Back to search

CVE-2021-38294

Published: Oct 25, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.

VendorProductVersions

Apache Software Foundation

Apache Storm

affected
v1.0.0 - < Apache Storm*

Apache Software Foundation

Apache Storm

affected
Apache Storm - < v1.2.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now