CVE-2014-0115: Apache Storm

High severity, CVSS 7.5. EPSS: 5.3% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.

Affected products

  • Apache Storm: version 0.9.0.1 only

Published 2017-10-30. Last modified 2026-06-17.