Vulnerability record · CVE-2021-40865 · published 25 October 2021
CVE-2021-40865: Apache Storm supervisor worker unsafe deserialization RCE
Apache · Storm
Apache Storm's supervisor worker services deserialize untrusted data, allowing an unauthenticated attacker to execute arbitrary code. The flaw is rated CVSS 9.8 critical and affects the Storm 1.x, 2.1.x and 2.2.x lines, with fixes in 1.2.4, 2.1.1, 2.2.1 and 2.3.0. Because it is pre-auth and network reachable, any exposed supervisor is at serious risk.
Description
An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1. Apache Storm 1.x users should upgrade to version 1.2.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-auth network RCE with CVSS 9.8 and very high EPSS makes this an urgent patch for any exposed Apache Storm supervisor.
What it is
Apache Storm's supervisor worker services deserialize untrusted data, allowing an unauthenticated attacker to execute arbitrary code. The flaw is rated CVSS 9.8 critical and affects the Storm 1.x, 2.1.x and 2.2.x lines, with fixes in 1.2.4, 2.1.1, 2.2.1 and 2.3.0. Because it is pre-auth and network reachable, any exposed supervisor is at serious risk.
Impact
An attacker gains remote code execution on the supervisor host with the privileges of the Storm service, enabling full compromise of the node and any data or credentials it can reach.
Attack surface
Reached over the network via the supervisor's worker services; the CVSS vector shows no privileges or user interaction required. Any supervisor port exposed beyond a trusted network is a candidate entry point.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is 0.65587 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Upgrade to the fixed release for your branch: 1.2.4 (1.x), 2.1.1 (2.1.x), 2.2.1 or 2.3.0 (2.2.x).
- If immediate upgrade is not possible, restrict network access to supervisor and worker ports to trusted hosts only.
- Place supervisors behind a firewall or VPN and avoid exposing them to the internet.
- Monitor Apache Storm security advisories for follow-up fixes or backports.
- Verify the upgrade actually replaced running worker processes, not just the installed package.
Detection
- Alert on unexpected outbound connections or child processes spawned by Storm supervisor/worker JVMs.
- Monitor supervisor and worker ports for connections from untrusted source addresses.
- Look for anomalous deserialization-related errors or crashes in Storm supervisor logs.
- Baseline normal worker traffic and flag deviations in volume or destination.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.or | Mailing ListVendor Advisory |
| https://seclists.org/oss-sec/2021/q4/45 | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread.html/r8d45e74299897b6734dd0f788c46a631009ce2eeb731523386f7a253%40%3Cuser.storm.apache.or | Mailing ListVendor Advisory |
| https://seclists.org/oss-sec/2021/q4/45 | Mailing ListThird Party Advisory |
Track CVE-2021-40865 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40865), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.