suse · CVE-2017-9799

Quick triage

Priority: medium 公開: 2021-05-30 13:57:39 UTC Updated: 2023-12-08 01:28:58 UTC

参照: Official suse advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-9799 severity moderate: SUSE including 3 source package names (storm-1.0.5-5.3, storm-nimbus-1.0.5-5.3, storm-supervisor-1.0.5-5.3), 3 product×package rows across 1 product lines (SUSE OpenStack Cloud 7): Fixed 3.

Description:

It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised.

cvelogic Threat Intelligence