Security Advisory

CVE-2018-1331

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-07-10 17:00:00
Last updated 2024-09-16 17:48:08
Assigner apache
CVSS score not scored
State PUBLISHED

Description

In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.