Description
Description

`getNimbusConf` returned the complete daemon configuration without redaction after only a user-level
authorization check. Where the cluster is configured with them, that response includes
`storm.zookeeper.auth.payload` and the keystore and truststore passwords for the Thrift, Netty and
ZooKeeper TLS configuration. The project masks passwords elsewhere before display, so the omission here is
inconsistent rather than intended.

The UI endpoint `/api/v1/cluster/configuration` compounded this. It carried no `@AuthNimbusOp` annotation,
and the authorization filter treated a missing annotation as "no gate required" and returned immediately, so
the endpoint applied no per-user check at all and proxied the request under the UI daemon's own principal.
Any user able to pass `ui.filter` therefore received the full configuration, including principals that
Nimbus itself would have refused. 

Mitigation

Upgrade to 3.1.0, where credential-bearing values are masked before the configuration is served and where
every UI API endpoint must declare its authorization explicitly.

Users who cannot upgrade immediately should place the UI behind an authenticating reverse proxy that
restricts `/api/v1/cluster/configuration`, and should rotate the ZooKeeper authentication payload and any
TLS keystore or truststore passwords that were reachable through it.

Credit

The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality disclosure of daemon configuration including credentials
Action: Immediate Patch
AI Analysis

Impact

A function in Apache Storm, getNimbusConf, returns the complete daemon configuration without redacting sensitive entries such as Storm's Zookeeper authentication payload and TLS keystore and truststore passwords, despite performing only a superficial user-level authorization check. The UI API endpoint /api/v1/cluster/configuration further exposes the same configuration because it lacks explicit authorization handling, allowing any user who can pass ui.filter to retrieve the full configuration. This flaw gives attackers access to privileged credentials, constituting a confidentiality breach that aligns with CWE‑522 and CWE‑862 weaknesses.

Affected Systems

All installations of Apache Storm Nimbus and the Storm UI that are running prior to the 3.1.0 release are affected, as this release corrected the credential masking and required authorization annotations for all UI API endpoints. The affected vendors are Apache Software Foundation (Storm Nimbus) and Apache Software Foundation (Storm UI).

Risk and Exploitability

The vulnerability is scored as a 6.5 on the CVSS scale, representing a moderate severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation on the date of this assessment. Apache does not list the issue in its KEV catalog. Attackers would need authenticated access to the Nimbus or UI services with the ability to invoke the exposed endpoints; no additional software execution or privilege escalation is required beyond legitimate user access to the UI or Nimbus.

Generated by OpenCVE AI on September 21, 2026 at 00:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache Storm 3.1.0 or later, which masks credential‑bearing values and enforces explicit authorization for UI APIs.
  • Compensate temporarily by positioning a reverse proxy that authenticates requests and blocks access to /api/v1/cluster/configuration for unauthorized or non‑upgraded services.
  • Rotate the Zookeeper authentication payload and all TLS keystore or truststore passwords that could have been leaked through the exposed configuration.

Generated by OpenCVE AI on September 21, 2026 at 00:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and truststore passwords for the Thrift, Netty and ZooKeeper TLS configuration. The project masks passwords elsewhere before display, so the omission here is inconsistent rather than intended. The UI endpoint `/api/v1/cluster/configuration` compounded this. It carried no `@AuthNimbusOp` annotation, and the authorization filter treated a missing annotation as "no gate required" and returned immediately, so the endpoint applied no per-user check at all and proxied the request under the UI daemon's own principal. Any user able to pass `ui.filter` therefore received the full configuration, including principals that Nimbus itself would have refused.  Mitigation Upgrade to 3.1.0, where credential-bearing values are masked before the configuration is served and where every UI API endpoint must declare its authorization explicitly. Users who cannot upgrade immediately should place the UI behind an authenticating reverse proxy that restricts `/api/v1/cluster/configuration`, and should rotate the ZooKeeper authentication payload and any TLS keystore or truststore passwords that were reachable through it. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Title Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI
Weaknesses CWE-522
CWE-862
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T20:02:43.408Z

Reserved: 2026-08-29T10:25:15.578Z

Link: CVE-2026-82433

cve-icon Vulnrichment

Updated: 2026-09-14T14:13:29.105Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:10.323

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-82433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials

  • CWE-862

    Missing Authorization