Impact
The vulnerability arises when the setuid-root worker‑launcher first changes the ownership of the entire worker directory to an untrusted topology user and subsequently reads and executes a command file written by the supervisor. The file is opened without the O_NOFOLLOW flag and without re‑verifying its owner, creating a window during which an attacker can replace the file’s contents while it is owned by that user. The likely attack vector is a tenant who can submit a topology, as such a tenant can place a malicious command file in the directory between the ownership change and the read. In the Docker execution path the rewritten command is parsed and executed with real UID 0; the command sanitizer does not provide a privilege boundary and allows options such as –v, --device, --cap-add, --security‑opt, --user and –net, passing positional arguments verbatim. Consequently an attacker can launch a root‑equivalent container invocation with the host filesystem available. The OCI path has an equivalent race; the mount validation is structural only, permitting arbitrary host paths to be bind‑mounted read‑write into the container. The username field in the command file is also attacker‑settable and is only checked against non‑root and minimum‑uid rules, enabling execution as another tenant’s UID. This results in a tenant who can submit a topology being able to execute commands as root on the worker host, a classic example of a race condition (CWE‑367).
Affected Systems
All instances of the Apache Storm Worker Launcher that rely on the setuid-root worker‑launcher component are vulnerable. Versions deployed prior to the public release of 3.1.0 contain the race; the vendor recommends upgrading to 3.1.0 or later where command files are validated before the ownership change and source/destination mounts are constrained by configuration.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. EPSS score is < 1%, and the issue is not listed in KEV; local access to the worker node or the ability to submit a topology is required, and network isolation alone does not mitigate the problem. The clear attack path and high impact make the priority for remediation high. The risk is compounded by the fact that the attacker can gain root privileges on the host, giving complete control over the system.
OpenCVE Enrichment