Impact
The vulnerability in Apache Storm's SimpleACLAuthorizer causes the ACL check to return early when the nimbus.users list is empty, ignoring the group list set in nimbus.groups. An operator who configures access control solely by group without specifying any users therefore experiences no restriction-level permissions, including the ability to submit topologies, upload files, and retrieve Nimbus configuration. This flaw enables an attacker who can authenticate with valid credentials to execute any privileged operation and effectively gain full control over the cluster. Based on the description, it is inferred that the attacker can manipulate topological deployment and file uploads, thus impacting confidentiality, integrity, and availability.
Affected Systems
Apache Storm Client deployments that have nimbus.groups configured but leave nimbus.users unset are affected. All releases prior to 3.1.0 contain the logic error; version 3.1.0 and later correct the evaluation so that group restrictions are applied regardless of the user list.
Risk and Exploitability
The CVSS score of 9.8 reflects a high severity, authenticated-level threat; an attacker only needs to obtain or reuse a valid principal name. The EPSS score is less than 1 %, indicating that currently no widespread exploitation is observed, but the absence of a KEV listing does not diminish the critical severity. The bug can be exploited remotely via any Storm client that authenticates to Nimbus, giving the attacker full cluster access. Based on the description, it is inferred that the likely attack vector involves a remote client authenticating to Nimbus, as the logic flaw is triggered when credentials are presented to the Storm client.
OpenCVE Enrichment