Apache Storm 0.10.0-beta Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 24 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    The UI daemon in Apache Storm version 0.10.0-beta allows remote users to run arbitrary code as the user running the web server. With kerberos authentication this could allow impersonation of arbitrary users on other systems, including HDFS and HBase.

    Continue reading...
     

Share This Page

Loading...