CVE Published: 10/07/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Storm Status : PUBLISHED
CVE-2018-1331 Description
In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.