CVE-2021-40865

CRITICAL

Apache Storm <2.2.1, <2.3.0, <1.2.4 - Open Redirect

Title source: llm

Description

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4

Exploits (1)

nomisec WORKING POC 14 stars
by hktalent · poc
https://github.com/hktalent/CVE-2021-40865

Scores

CVSS v3 9.8
EPSS 0.4622
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

apache/storm < 1.2.4
org.apache.storm/storm < 2.2.1Maven

Timeline

Published Oct 25, 2021
Tracked Since Feb 18, 2026