Vulnerability Description
It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Storm | 1.0 |
References
- http://www.securityfocus.com/bid/100235Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039116Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/b9125bf507ed6f2ca6e85ba1a4b44e232aa70eeddfb
- http://www.securityfocus.com/bid/100235Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039116Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/b9125bf507ed6f2ca6e85ba1a4b44e232aa70eeddfb
FAQ
What is CVE-2017-9799?
CVE-2017-9799 is a vulnerability with a CVSS score of 8.8 (HIGH). It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to ...
How severe is CVE-2017-9799?
CVE-2017-9799 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9799?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Storm.