{"id":"GHSA-6768-mcjc-8223","summary":"Command injection leading to Remote Code Execution in Apache Storm","details":"A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.","aliases":["CVE-2021-38294"],"modified":"2023-11-08T04:06:27.082122Z","published":"2021-10-27T18:51:22Z","database_specific":{"github_reviewed_at":"2021-10-26T17:52:52Z","nvd_published_at":"2021-10-25T13:15:00Z","cwe_ids":["CWE-74","CWE-78"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-38294"},{"type":"PACKAGE","url":"https://github.com/apache/storm"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r5fe881f6ca883908b7a0f005d35115af49f43beea7a8b0915e377859%40%3Cuser.storm.apache.org%3E"},{"type":"WEB","url":"https://seclists.org/oss-sec/2021/q4/44"},{"type":"WEB","url":"http://packetstormsecurity.com/files/165019/Apache-Storm-Nimbus-2.2.0-Command-Execution.html"}],"affected":[{"package":{"name":"org.apache.storm:storm","ecosystem":"Maven","purl":"pkg:maven/org.apache.storm/storm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.1"}]}],"versions":["2.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-6768-mcjc-8223/GHSA-6768-mcjc-8223.json"}},{"package":{"name":"org.apache.storm:storm","ecosystem":"Maven","purl":"pkg:maven/org.apache.storm/storm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.1.1"}]}],"versions":["2.0.0","2.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-6768-mcjc-8223/GHSA-6768-mcjc-8223.json"}},{"package":{"name":"org.apache.storm:storm","ecosystem":"Maven","purl":"pkg:maven/org.apache.storm/storm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.2.4"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.1.0","1.1.1","1.1.2","1.1.3","1.2.0","1.2.1","1.2.2","1.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-6768-mcjc-8223/GHSA-6768-mcjc-8223.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}