Vulnerability record · CVE-2021-38294 · published 25 October 2021
CVE-2021-38294: Apache Storm Nimbus getTopologyHistory pre-auth command injection
Apache · Storm
Apache Storm's Nimbus getTopologyHistory service fails to neutralize input in a Thrift request, allowing OS command injection. The flaw affects Storm 2.x before 2.2.1 and 1.x before 1.2.4 and is reachable before authentication, so any host that can reach the Nimbus Thrift port can attempt it.
Description
A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with pre-auth network RCE and very high EPSS make this an urgent patch target.
What it is
Apache Storm's Nimbus getTopologyHistory service fails to neutralize input in a Thrift request, allowing OS command injection. The flaw affects Storm 2.x before 2.2.1 and 1.x before 1.2.4 and is reachable before authentication, so any host that can reach the Nimbus Thrift port can attempt it.
Impact
An unauthenticated attacker can execute arbitrary operating system commands on the Nimbus server, leading to full compromise of the host and the cluster it manages.
Attack surface
Reached over the network via a specially crafted Thrift request to the Nimbus server; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.845, 99.7th percentile) and public exploit code is referenced on Packet Storm, indicating active interest and easy weaponization.
What to do
- Upgrade Apache Storm to 2.2.1 or later (2.x) or 1.2.4 or later (1.x).
- Restrict network access to the Nimbus Thrift port to trusted hosts only.
- Place Nimbus behind a firewall or VPN and avoid exposing it to untrusted networks.
- Monitor for and block anomalous Thrift requests to the getTopologyHistory service.
- If patching is delayed, isolate Nimbus hosts from sensitive internal networks.
Detection
- Monitor Nimbus logs for errors or unusual activity around getTopologyHistory calls.
- Inspect network traffic to the Nimbus Thrift port for malformed or unexpected requests.
- Alert on child processes spawned by the Storm Nimbus JVM, especially shell or command interpreters.
- Review host process telemetry for command execution originating from the Nimbus service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165019/Apache-Storm-Nimbus-2.2.0-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://lists.apache.org/thread.html/r5fe881f6ca883908b7a0f005d35115af49f43beea7a8b0915e377859%40%3Cuser.storm.apache.or | Mailing ListVendor Advisory |
| https://seclists.org/oss-sec/2021/q4/44 | Mailing ListThird Party Advisory |
| http://packetstormsecurity.com/files/165019/Apache-Storm-Nimbus-2.2.0-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://lists.apache.org/thread.html/r5fe881f6ca883908b7a0f005d35115af49f43beea7a8b0915e377859%40%3Cuser.storm.apache.or | Mailing ListVendor Advisory |
| https://seclists.org/oss-sec/2021/q4/44 | Mailing ListThird Party Advisory |
Track CVE-2021-38294 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-38294), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.