CVE-2021-40865

CRITICAL

Apache Storm <2.2.1, <2.3.0, <1.2.4 - Open Redirect

Title source: llm
STIX 2.1

Description

An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4

Exploits (1)

nomisec WORKING POC 14 stars
by hktalent · poc
https://github.com/hktalent/CVE-2021-40865

References (2)

Core 2
Core References
Mailing List, Third Party Advisory x_refsource_misc
https://seclists.org/oss-sec/2021/q4/45

Scores

CVSS v3 9.8
EPSS 0.4622
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (2)
apache/storm 1.0.0 - 1.2.4
org.apache.storm/storm 2.2.0 - 2.2.1Maven
Published Oct 25, 2021
Tracked Since Feb 18, 2026