Impact
The flaw allows a user who can rebalance a topology to insert a blobstore map entry that references a blob whose access control list does not grant that user read permission, so the blob’s contents are inadvertently copied into the topology’s working directory. In addition, the listBlobs operation performs no authorization check and can be invoked by any caller that can reach the Nimbus Thrift port, creating a metadata leak of every blob key that can be used to retrieve unwanted data. Together these issues enable privileged users to access or exfiltrate internal Storm configuration and data stored in the blobstore.
Affected Systems
Apache Storm Nimbus installations that have not applied the 3.1.0 or later updates are affected. The vulnerability exists in all earlier versions of the Nimbus component and can impact any deployment that relies on the default configuration of the rebalance operation and blob listing APIs.
Risk and Exploitability
The CVSS score of 8.1 denotes a high severity vulnerability. Although the EPSS score is less than 1 %, the issue is not listed in CISA’s KEV catalog. The likely attack vector is remote; an attacker only needs to reach the Nimbus Thrift service to exploit listBlobs or to use the rebalance operation as a privileged user. Once the attack is launched, the attacker can read arbitrary blob contents, potentially leading to data compromise or further lateral movement if the blob contains configuration or code useful to an attacker. The lack of re‑validation of rebalance configuration overrides makes exploitation straightforward for a correctly privileged user.
OpenCVE Enrichment