[CVEID]:CVE-2018-1320[PRODUCT]:Apache Storm[VERSION]:Apache Storm 0.9.1-incubating to 1.2.2[PROBLEMTYPE]:CWE-20: Input Validation[DESCRIPTION]:Apache Storm versions 0.9.1-incubating to 1.2.2 use Thrift library versions vulnerable to CVE-2018-1320.
Mitigation: Upgrade to Apache Storm 1.2.3 or later. Credit: Arun Mahadevan for discovery and fix