The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-5140 The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.
Github GHSA Github GHSA GHSA-r9pv-hg64-jqrp Exposure of Sensitive Information in Apache Storm Logviewer
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T17:44:14.845Z

Reserved: 2018-11-14T00:00:00

Link: CVE-2019-0202

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-26T00:15:11.027

Modified: 2024-11-21T04:16:28.710

Link: CVE-2019-0202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.