← Back to CVE List

CVE-2021-40865

Published: 2021-10-25T13:15Z
Last Modified: 2024-11-21T06:24Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4 > MITRE Terms of Use apply – see LICENSE‑MITRE.txt