User Impersonation Vulnerability in Apache Storm by The Apache Software Foundation
CVE-2017-9799
8.8HIGH
What is CVE-2017-9799?
A potential user impersonation vulnerability exists in Apache Storm due to improper handling of configurations. Under specific conditions, an owner of a topology could manipulate the system to execute a worker process under the context of another non-root user. This situation heightens the risk of exposing sensitive credentials belonging to that user, leading to possible unauthorized access or escalation of privileges.
Affected Version(s)
Apache Storm 1.0.0 through 1.0.3
Apache Storm 1.1.0