Impact
A function in Apache Storm, getNimbusConf, returns the complete daemon configuration without redacting sensitive entries such as Storm's Zookeeper authentication payload and TLS keystore and truststore passwords, despite performing only a superficial user-level authorization check. The UI API endpoint /api/v1/cluster/configuration further exposes the same configuration because it lacks explicit authorization handling, allowing any user who can pass ui.filter to retrieve the full configuration. This flaw gives attackers access to privileged credentials, constituting a confidentiality breach that aligns with CWE‑522 and CWE‑862 weaknesses.
Affected Systems
All installations of Apache Storm Nimbus and the Storm UI that are running prior to the 3.1.0 release are affected, as this release corrected the credential masking and required authorization annotations for all UI API endpoints. The affected vendors are Apache Software Foundation (Storm Nimbus) and Apache Software Foundation (Storm UI).
Risk and Exploitability
The vulnerability is scored as a 6.5 on the CVSS scale, representing a moderate severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation on the date of this assessment. Apache does not list the issue in its KEV catalog. Attackers would need authenticated access to the Nimbus or UI services with the ability to invoke the exposed endpoints; no additional software execution or privilege escalation is required beyond legitimate user access to the UI or Nimbus.
OpenCVE Enrichment