Impact
A topology’s topology.blobstore.map lets a submitter choose a local name for each blob the supervisor localises, and that name is used to construct a file‑system path without normalisation. The code deletes whatever exists at the target before creating a symlink. By including parent‑directory traversal segments, an attacker can delete arbitrary supervisor‑owned content and plant a malicious symlink. When a worker subsequently launches using that symlink, the code runs under the tenant’s operating‑system user, undermining the isolation intended by supervisor.run.worker.as.user. The flaw is a path traversal weakness (CWE‑22).
Affected Systems
Apache Storm Nimbus installations prior to version 3.1.0 are affected. The vulnerability exists in all releases that do not enforce path normalization on topology.blobstore.map entries.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is less than 1%, reflecting a currently low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to submit a topology containing a topology.blobstore.map entry with path traversal components; the supervisor user on each node processes the submission, allowing file deletion or symlink creation. This can lead to loss of data, leakage of files, and execution of arbitrary code with the privileges of a tenant’s OS user, effectively subverting tenant isolation.
OpenCVE Enrichment