← Vulnerability feed

Vulnerability record · CVE-2021-38294 · published 25 October 2021

CVE-2021-38294: Apache Storm Nimbus getTopologyHistory pre-auth command injection

Apache · Storm

Apache Storm's Nimbus getTopologyHistory service fails to neutralize input in a Thrift request, allowing OS command injection. The flaw affects Storm 2.x before 2.2.1 and 1.x before 1.2.4 and is reachable before authentication, so any host that can reach the Nimbus Thrift port can attempt it.

9.8 CVSS 3.1 Critical EPSS 84% · top 0.3% CWE-74 · InjectionCWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 7.5
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with pre-auth network RCE and very high EPSS make this an urgent patch target.

What it is

Apache Storm's Nimbus getTopologyHistory service fails to neutralize input in a Thrift request, allowing OS command injection. The flaw affects Storm 2.x before 2.2.1 and 1.x before 1.2.4 and is reachable before authentication, so any host that can reach the Nimbus Thrift port can attempt it.

Impact

An unauthenticated attacker can execute arbitrary operating system commands on the Nimbus server, leading to full compromise of the host and the cluster it manages.

Attack surface

Reached over the network via a specially crafted Thrift request to the Nimbus server; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.845, 99.7th percentile) and public exploit code is referenced on Packet Storm, indicating active interest and easy weaponization.

What to do

  • Upgrade Apache Storm to 2.2.1 or later (2.x) or 1.2.4 or later (1.x).
  • Restrict network access to the Nimbus Thrift port to trusted hosts only.
  • Place Nimbus behind a firewall or VPN and avoid exposing it to untrusted networks.
  • Monitor for and block anomalous Thrift requests to the getTopologyHistory service.
  • If patching is delayed, isolate Nimbus hosts from sensitive internal networks.

Detection

  • Monitor Nimbus logs for errors or unusual activity around getTopologyHistory calls.
  • Inspect network traffic to the Nimbus Thrift port for malformed or unexpected requests.
  • Alert on child processes spawned by the Storm Nimbus JVM, especially shell or command interpreters.
  • Review host process telemetry for command execution originating from the Nimbus service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-38294 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40865Apache Storm supervisor worker unsafe deserialization RCEApache Storm's supervisor worker services deserialize untrusted data, allowing an unauthenticated attacker to execute arbitrary code. The flaw is rat…EPSS 64%analysed9.8CVE-2018-11779Apache storm deserialization of untrusted data vulnerabilityIn Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI d…EPSS 3.5%9.8CVE-2015-3188Apache storm permissions and access controls vulnerabilityThe UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 14%8.8CVE-2026-35337Apache storm deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials s…EPSS 1.1%8.8CVE-2018-1331Apache storm vulnerabilityIn Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm c…EPSS 4.4%8.8CVE-2017-9799Apache storm vulnerabilityIt was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for …EPSS 4.9%7.5CVE-2019-0202Apache storm information exposure vulnerabilityThe Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i…EPSS 2.0%7.5CVE-2014-0115Apache storm path traversal vulnerabilityDirectory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the…EPSS 5.3%

Source: NIST National Vulnerability Database (record CVE-2021-38294), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.