Apache Storm Remote Code Execution Vulnerability (CVE-2015-3188)
Apache Storm Remote Code Execution Vulnerability (CVE-2015-3188)
Release date:
Updated on:
Affected Systems:
Apache Group Storm 0.10.0-beta
Unaffected system:
Apache Group Storm 0.10.0-beta1
Description:
Bugtraq id: 75338
CVE (CAN) ID: CVE-2015-3188
Apache Storm is a free open-source distributed real-time computing system.
The UI daemon in Apache Storm 0.10.0-beta has the remote code execution vulnerability, which allows remote users to run arbitrary code with the current user permission.
<* Source: Bobby Evans
Link: http://www.securityfocus.com/archive/1/535804
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/apache/storm/blob/v0.10.0-beta1/SECURITY.md
Https://github.com/apache/storm/blob/v0.10.0-beta1/STORM-UI-REST-API.md
Storm Process Communication Mechanism Analysis
Apache Storm History and Lessons
For details about Apache Storm, click here
Apache Storm: click here
This article permanently updates the link address: