The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.apache.storm:storm-server to version 3.1.0 or higher.
org.apache.storm:storm-server is a distributed realtime computation system.
Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the getNimbusConf process. An attacker can obtain sensitive configuration data, including authentication payloads and keystore or truststore passwords, by making unauthorized requests to the affected endpoints. This is possible because the configuration is returned without redaction after only a user-level authorization check, and the UI endpoint /api/v1/cluster/configuration does not enforce per-user authorization, allowing any user able to pass ui.filter to access the full configuration.
This vulnerability can be mitigated by placing the UI behind an authenticating reverse proxy that restricts access to /api/v1/cluster/configuration, and by rotating any exposed authentication payloads and passwords.