CVE-2019-0202

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:storm:0.9.1:incubating:*:*:*:*:*:*
cpe:2.3:a:apache:storm:0.9.2:incubating:*:*:*:*:*:*

History

07 Nov 2023, 03:01

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/220f1a77ff20749326a4c130446c5521db854da0afe81d1974b8109f@%3Cuser.storm.apache.org%3E', 'name': '[storm-user] 20190724 [CVE-2019-0202] Apache Storm Logviewer file system access vulnerability', 'tags': ['Mailing List', 'Vendor Advisory'], 'refsource': 'MLIST'}
  • () https://lists.apache.org/thread.html/220f1a77ff20749326a4c130446c5521db854da0afe81d1974b8109f%40%3Cuser.storm.apache.org%3E -

Information

Published : 2019-07-26 00:15

Updated : 2023-12-10 12:59


NVD link : CVE-2019-0202

Mitre link : CVE-2019-0202

CVE.ORG link : CVE-2019-0202


JSON object : View

Products Affected

apache

  • storm
CWE
CWE-532

Insertion of Sensitive Information into Log File

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor