CVE-2023-43123: Apache Storm: Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files

2023-11-23 Thread Julien Nioche
Severity: low Affected versions: - Apache Storm 2.0.0 before 2.6.0 Description: On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure.

Re: [ANNOUNCE] Apache Storm 2.6.0 Released

2023-11-23 Thread Jonas Krauss
Great update, many thanks storm team! Am Do., 23. Nov. 2023 um 09:53 Uhr schrieb Julien Nioche : > The Apache Storm community is pleased to announce the release of Apache > Storm version 2.6.0. > > Apache Storm is a distributed, fault-tolerant, and high-performance > realtime computation system t

[ANNOUNCE] Apache Storm 2.6.0 Released

2023-11-23 Thread Julien Nioche
The Apache Storm community is pleased to announce the release of Apache Storm version 2.6.0. Apache Storm is a distributed, fault-tolerant, and high-performance realtime computation system that provides strong guarantees on the processing of data. You can read more about Apache Storm on the projec