CVE-2019-0202: Apache Storm

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpoints.

Affected products

  • Apache Storm: from 0.9.3, up to and including 1.2.2; version 0.9.1 only; version 0.9.2 only

Published 2019-07-26. Last modified 2026-06-17.