Medium severity5.5NVD Advisory· Published Jun 5, 2018· Updated Jun 17, 2026
CVE-2018-8008
CVE-2018-8008
Description
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.storm:storm-coreMaven | >= 1.1.0, < 1.1.3 | 1.1.3 |
org.apache.storm:storm-coreMaven | >= 1.2.0, < 1.2.2 | 1.2.2 |
org.apache.storm:storm-coreMaven | < 1.0.7 | 1.0.7 |
Affected products
2Patches
Vulnerability mechanics
References
9- www.securityfocus.com/bid/104418nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-898j-5cc8-cmf5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-8008ghsaADVISORY
- github.com/apache/storm/commit/0fc6b522487c061f89e8cdacf09f722d3f20589ghsaWEB
- github.com/apache/storm/commit/efad4cca2d7d461f5f8c08a0d7b51fabeb82d0aghsaWEB
- github.com/apache/storm/commit/f61e5daf299d6c37c7ad65744d02556c94a16a4ghsaWEB
- issues.apache.org/jira/browse/STORM-3052ghsaWEB
- lists.apache.org/thread.html/613b2fca8bcd0a3b12c0b763ea8f7cf62e422e9f79fce6cfa5b08a58@%3Cdev.storm.apache.org%3EghsaWEB
- lists.apache.org/thread.html/613b2fca8bcd0a3b12c0b763ea8f7cf62e422e9f79fce6cfa5b08a58%40%3Cdev.storm.apache.org%3Envd
News mentions
0No linked articles in our index yet.