CVE-2021-38294 is an OS command injection vulnerability in Apache Storm's Nimbus getTopologyHistory service. A remote attacker can submit a specially crafted Thrift request that causes attacker-controlled input to be incorporated into an operating-system command. The vulnerable service processes the request before authentication, enabling unauthenticated remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting an unauthenticated command injection vulnerability (CVE-2021-38294) in the Apache Storm Nimbus service. The exploit leverages the 'getTopologyHistory' Thrift RPC method, which unsafely concatenates user input into a bash command, allowing remote attackers to execute arbitrary commands on the server. The module supports both direct command execution and staged payload delivery (e.g., reverse shell, Meterpreter) using Metasploit's payload system. The default target port is 6627, which is the standard Thrift service port for Nimbus. The exploit requires that at least one topology has been submitted to the server. The code is written in Ruby and is fully integrated into the Metasploit framework, providing weaponized exploitation capabilities. No hardcoded IPs or URLs are present, but the module is designed to be used against network-accessible Apache Storm Nimbus instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.