Impact
The setuid‑root worker‑launcher binary in Apache Storm modifies worker directory ownership and permissions by walking the filesystem with FTS and invoking lchown and chmod on each pathname while running with effective UID 0. The binary resolves the path again at each syscall, creating a time‑of‑check to time‑of‑use race. An attacker who can replace an intermediate directory component with a symbolic link between classification of a file and the privileged operation, causing the subsequent lchown or chmod to operate on an arbitrary host file. This allows the attacker to change ownership or permissions of critical files and ultimately gain root privileges, thereby violating supervisor isolation intended by supervisor.run.worker.as.user.
Affected Systems
The flaw affects the Apache Storm Worker Launcher component in all releases prior to 3.1.0. Systems running older versions of Storm on supervisor nodes where the worker‑launcher binary is setuid‑root are vulnerable. The issue is tied to the privileged walk performed during worker directory creation and updates, so any deployment that does not upgrade to the hardened version is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. With no protection against the time‑of‑check race, an attacker can repeatedly exercise the flaw by causing a worker crash and. Because the attacker only needs to run untrusted topology code on a supervisor configured for worker‑as‑user, the attack vector is local and achievable from within on existing network access and can be performed entirely from tenant‑provided code. While the EPSS score is less than 1% (approximately 0.00131) and the vulnerability is not listed in CISA's KEV catalog, its nature and high severity make it a significant risk to any cluster that has not yet adopted the 3.1.0 fix.
OpenCVE Enrichment