Impact
Dependency artifacts uploaded with storm jar --artifacts were stored under a blob key derived solely from the Maven coordinate, resulting in identical, predictable keys for all users. When a blob already existed, the uploader silently reused it without verifying the blob’s content or owner. A malicious user can therefore upload a malicious JAR under a predictable key that future submitters will load into their worker classpath, enabling remote code execution inside another tenant’s topology. The weakness is a form of arbitrary artifact substitution, categorized as CWE‑22.
Affected Systems
Apache Software Foundation’s Apache Storm Client is affected. The vulnerability exists when multiple principals may create blobs and the --artifacts dependency feature is used. Upgrading to 3.1.0 or a newer release resolves the issue.
Risk and Exploitability
Based on the description, the likely attack vector is a trusted user executing storm jar --artifacts. The CVSS score of 8.8 classifies this as high severity. The EPSS score of < 1% indicates a very low probability of exploitation, but the vulnerability can be exploited in multi‑tenant clusters where users can submit artifacts. Because the exploit results in code execution on worker nodes, the impact on confidentiality, integrity, and availability is significant. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment