CVE-2021-40865
Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm
9.8
CRITICAL
CVSS 3.1
EPSS 46.2%
Description
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4
How to fix CVE-2021-40865
To remediate CVE-2021-40865, upgrade the affected package to a fixed version below.
- —upgrade to 2.2.1 or later
Is CVE-2021-40865 being exploited?
Moderate — EPSS is 46.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 2.2.0, < 2.2.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |