Show plain JSON{"containers": {"cna": {"affected": [{"product": "Apache Storm", "vendor": "Apache Software Foundation", "versions": [{"lessThan": "Apache Storm *", "status": "affected", "version": "v1.0.0", "versionType": "custom"}, {"changes": [{"at": "v2.1.1", "status": "unaffected"}, {"at": "v2.2.1", "status": "unaffected"}, {"at": "v2.3.0", "status": "unaffected"}], "lessThan": "v1.2.4", "status": "affected", "version": "Apache Storm", "versionType": "custom"}]}], "credits": [{"lang": "en", "value": "Apache Storm would like to thank @pwntester Alvaro Mu\u00f1oz of the GitHub Security Lab team for reporting this issue."}], "descriptions": [{"lang": "en", "value": "An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4"}], "metrics": [{"other": {"content": {"other": "high"}, "type": "unknown"}}], "problemTypes": [{"descriptions": [{"cweId": "CWE-502", "description": "CWE-502 Deserialization of Untrusted Data", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"dateUpdated": "2021-10-25T12:22:37", "orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09", "shortName": "apache"}, "references": [{"tags": ["x_refsource_MISC"], "url": "https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.org%3E"}, {"tags": ["x_refsource_MISC"], "url": "https://seclists.org/oss-sec/2021/q4/45"}], "source": {"discovery": "UNKNOWN"}, "title": "Unsafe Pre-Authentication Deserialization In Workers", "workarounds": [{"lang": "en", "value": "Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0\nApache Storm 2.1.x users should upgrade to version 2.1.1\nApache Storm 1.x users should upgrade to version 1.2.4"}], "x_generator": {"engine": "Vulnogram 0.0.9"}, "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "security@apache.org", "ID": "CVE-2021-40865", "STATE": "PUBLIC", "TITLE": "Unsafe Pre-Authentication Deserialization In Workers"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "Apache Storm", "version": {"version_data": [{"version_affected": ">=", "version_name": "Apache Storm ", "version_value": "v1.0.0"}, {"version_affected": "<", "version_name": "Apache Storm", "version_value": "v1.2.4"}, {"version_affected": "<", "version_name": "Apache Storm", "version_value": "v2.1.1"}, {"version_affected": "<", "version_name": "Apache Storm", "version_value": "v2.2.1"}, {"version_affected": "<", "version_name": "Apache Storm", "version_value": "v2.3.0"}]}}]}, "vendor_name": "Apache Software Foundation"}]}}, "credit": [{"lang": "eng", "value": "Apache Storm would like to thank @pwntester Alvaro Mu\u00f1oz of the GitHub Security Lab team for reporting this issue."}], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4"}]}, "generator": {"engine": "Vulnogram 0.0.9"}, "impact": [{"other": "high"}], "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "CWE-502 Deserialization of Untrusted Data"}]}]}, "references": {"reference_data": [{"name": "https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.org%3E", "refsource": "MISC", "url": "https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.org%3E"}, {"name": "https://seclists.org/oss-sec/2021/q4/45", "refsource": "MISC", "url": "https://seclists.org/oss-sec/2021/q4/45"}]}, "source": {"discovery": "UNKNOWN"}, "work_around": [{"lang": "en", "value": "Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0\nApache Storm 2.1.x users should upgrade to version 2.1.1\nApache Storm 1.x users should upgrade to version 1.2.4"}]}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-04T02:51:07.676Z"}, "title": "CVE Program Container", "references": [{"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.org%3E"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://seclists.org/oss-sec/2021/q4/45"}]}]}, "cveMetadata": {"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09", "assignerShortName": "apache", "cveId": "CVE-2021-40865", "datePublished": "2021-10-25T12:22:37", "dateReserved": "2021-09-12T00:00:00", "dateUpdated": "2024-08-04T02:51:07.676Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}