Impact
Apache Storm Nimbus accepts the uploadedJarLocation argument in submitTopology as a server‑side path without verifying that the file was first uploaded by the user. to point the argument at any file readable by the Nimbus daemon account. The file is then copied into the topology jar blob and made accessible to the submitting user through normal blob download RPCs. As a result, attackers can read sensitive configuration files such as the Nimbus Kerberos keytab, TLS private keys, and ZooKeeper authentication data, effectively giving them cluster‑wide administrative privileges. The vulnerability is a classic example of CWE‑22: Path Traversal or Arbitrary File Read.
Affected Systems
The flaw affects all Apache Storm Nimbus deployments that are not updated to version 3.1.0 or later. Systems running earlier releases, particularly those that leave nimbus.users unset and therefore permit any authenticated principal to submit topologies, are vulnerable. The remedy is to upgrade to 3.1.0 or newer where the submitted location is canonicalised and required to resolve inside the Nimbus inbox.
Risk and Exploitability
This vulnerability carries a CVSS score of 6.5, indicating moderate severity. The EPSS score is <1%, indicating a very low exploitation probability, and the lack of a KEV listing suggests no widespread exploitation yet. An attacker only needs to be an authenticated user with topology submission capabilities, which may be common when nimbus.users or nimbus.groups are not configured. Once exploited, the attacker can gain critical credentials and become a cluster administrator. The risk is therefore moderate to significant, especially in environments where the default configuration permits unrestricted topology submission.
OpenCVE Enrichment