Apache could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in the mysql jdbc connector parameters. By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Apache MINA is vulnerable to a denial of service, caused by a flaw in the HTTP Header decoder. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to cause the HTTP Header decoder to loop indefinitely, and results in a denial of service condition.
Upgrade to the latest version of Apache Storm, available from the Apache Web site.https://storm.apache.org/