CVE-2018-11779

CRITICAL

Apache Storm 1.1.0-1.2.2 - Deserialization of Untrusted Data via Storm UI Daemon

Title source: llm
STIX 2.1

Description

In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0147
EPSS Percentile 81.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (3)
apache/storm 1.1.0 - 1.2.2
org.apache.storm/storm-kafka 1.1.0 - 1.2.3Maven
org.apache.storm/storm-kafka-client 1.1.0 - 1.2.3Maven
Published Jul 26, 2019
Tracked Since Feb 18, 2026