In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
{
"severity": "CRITICAL",
"github_reviewed_at": "2019-08-01T17:52:52Z",
"nvd_published_at": "2019-07-26T00:15:00Z",
"cwe_ids": [
"CWE-502"
],
"github_reviewed": true
}