CVE-2019-0202 is a high-severity information disclosure vulnerability affecting Apache Storm versions 0.9.1-incubating through 1.2.2. The Apache Storm Logviewer daemon exposes HTTP endpoints that can be abused to read arbitrary files from the host's file system, beyond intended log files. This vulnerability has a CVSS score of 7.5, indicating a high risk due to its network-based attack vector, low complexity, and potential for complete confidentiality compromise. While no public exploit code or active exploitation has been observed, and community discussion is minimal, organizations using affected Apache Storm versions should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.9.3, <= 1.2.2CPE matchmatch criteria | cpe:2.3:a:apache:storm:*:*:*:*:*:*:*:* | ||
0.9.1CPE matchmatch criteria | cpe:2.3:a:apache:storm:0.9.1:incubating:*:*:*:*:*:* | ||
0.9.2CPE matchmatch criteria | cpe:2.3:a:apache:storm:0.9.2:incubating:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.