VendorsApachestormall versions
Vulnerabilities

Apache Software Foundation Storm

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2015-3188
The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.
Published 2017-01-13 · Modified
10.0EPSS 0.144
CVE-2021-38294
Shell Command Injection Vulnerability in Nimbus Thrift Server
Published 2021-10-25 · Modified
9.8EPSS 0.845
CVE-2021-40865
Unsafe Pre-Authentication Deserialization In Workers
Published 2021-10-25 · Modified
9.8EPSS 0.656
CVE-2018-11779
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
Published 2019-07-25 · Modified
9.8EPSS 0.035
CVE-2017-9799
It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised.
Published 2017-08-09 · Modified
8.8EPSS 0.049
CVE-2018-1331
In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.
Published 2018-07-10 · Modified
8.8EPSS 0.044
CVE-2026-35337
Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling
Published 2026-04-13 · Analyzed
8.8EPSS 0.010
CVE-2014-0115
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.
Published 2017-10-30 · Modified
7.8EPSS 0.053
CVE-2019-0202
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.
Published 2019-07-25 · Modified
7.5EPSS 0.020
CVE-2018-1332
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.
Published 2018-06-05 · Modified
6.5EPSS 0.015
CVE-2026-41081
Apache Storm Client: Anonymous principal assigned on TLS client certificate verification failure
Published 2026-04-27 · Analyzed
6.5EPSS 0.003
CVE-2018-8008
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
Published 2018-06-05 · Modified
5.8EPSS 0.023
CVE-2023-43123
Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files
Published 2023-11-23 · Modified
5.5EPSS 0.003
CVE-2026-35565
Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI
Published 2026-04-13 · Analyzed
5.4EPSS 0.005