Severity: high
Description:
An Unsafe Deserialization vulnerability exists in the worker services of the
Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE).
Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm
2.1.x users should upgrade to
Severity: high
Description:
A Command Injection vulnerability exists in the getTopologyHistory service of
the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A
specially crafted thrift request to the Nimbus server allows Remote Code
Execution (RCE) prior to