Sorry about the formatting on these, it looked fine in Gmail.

Den ons. 24. jul. 2019 kl. 09.24 skrev Stig Rohde Døssing <[email protected]>:

> [CVEID]:CVE-2018-11779[PRODUCT]:Apache Storm[VERSION]:Apache Storm 1.1.0 to 
> 1.2.2[PROBLEMTYPE]:CWE-502: Deserialization of Untrusted Data[DESCRIPTION]:In 
> Apache Storm versions 1.1.0 to 1.2.2,
>               when the user is using the storm-kafka-client or storm-kafka 
> modules,
>               it is possible to cause the Storm UI daemon to deserialize user 
> provided bytes into a Java class.
>
> Mitigation: Upgrade to Apache Storm 1.2.3 or later.
>
> Credit: Bobby Evans for discovery and fix
>
>

Reply via email to