GHSA-w729-7633-2fw5
GitHub Security Advisory
Deserialization of Untrusted Data leading to Remote Code Execution in Apache Storm
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4
Affected Packages
Maven
org.apache.storm:storm
Affected versions:
2.2.0
(fixed in 2.2.1)
Maven
org.apache.storm:storm
Affected versions:
1.0.0
(fixed in 1.2.4)
Maven
org.apache.storm:storm
Affected versions:
2.1.0
(fixed in 2.1.1)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 28, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.