What the vulnerability does

01Description

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.

Key dates

02Disclosure timeline

July 25, 2019 CVE published
August 4, 2024 Record updated