Description
It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0712 | It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised. |
Github GHSA |
GHSA-x825-rjww-2245 | Apache Storm it is possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T02:06:16.001Z
Reserved: 2017-06-21T00:00:00.000Z
Link: CVE-2017-9799
No data.
Status : Deferred
Published: 2017-08-09T21:29:01.633
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-9799
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA