In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2018-07-10T17:00:00Z
Updated: 2024-09-16T17:48:08.492Z
Reserved: 2017-12-07T00:00:00
Link: CVE-2018-1331
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-07-10T17:29:00.213
Modified: 2024-11-21T03:59:38.380
Link: CVE-2018-1331
Redhat
No data.