CVE-2019-0202
26.07.2019, 00:15
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.Enginsight
Vendor | Product | Version |
---|---|---|
apache | storm | 0.9.3 ≤ 𝑥 ≤ 1.2.2 |
apache | storm | 0.9.1:incubating |
apache | storm | 0.9.2:incubating |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-532 - Insertion of Sensitive Information into Log FileInformation written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.