A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.
{
"cpe": "cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.2.4"
},
{
"introduced": "2.1.0"
},
{
"fixed": "2.1.1"
},
{
"introduced": "2.2.0"
},
{
"fixed": "2.2.1"
}
]
}