CVE-2018-11779: Apache Storm
Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
Affected products
- Apache Storm: from 1.1.0, up to and including 1.2.2
Published 2019-07-26. Last modified 2026-06-17.