CVE-2018-11779
26.07.2019, 00:15
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.Enginsight
Vendor | Product | Version |
---|---|---|
apache | storm | 1.1.0 ≤ 𝑥 ≤ 1.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration