VYPR
Critical severity9.8NVD Advisory· Published Oct 25, 2021· Updated Jun 17, 2026

CVE-2021-38294

CVE-2021-38294

Description

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.storm:stormMaven
>= 2.2.0, < 2.2.12.2.1
org.apache.storm:stormMaven
>= 2.0.0, < 2.1.12.1.1
org.apache.storm:stormMaven
>= 1.0.0, < 1.2.41.2.4

Affected products

3
  • Apache/Storm2 versions
    cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:*range: >=1.0.0,<1.2.4
    • (no CPE)range: Apache Storm
  • ghsa-coords
    Range: >= 2.2.0, < 2.2.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.