Impact
Apache Storm Nimbus and Client have a flaw where the Zookeeper topology authentication payload is included in the topology configuration that is accessible to users with only read‑only topology permissions. The exposed credential is not read‑only; it grants write‑capable ACLs for worker heartbeats, backpressure and error state. An attacker who obtains the payload can forge or delete state for the affected topology, effectively tampering with cluster operation and potentially disrupting service. This constitutes a serious breach of confidentiality, integrity, and availability for any Storm deployment that authenticates to Zookeeper.
Affected Systems
The vulnerability affects Apache Storm Client and Nimbus. No specific product versions are listed, but the advisory specifies that upgrading to version 3.1.0 removes the problematic payload from served configurations and stops logging the credential. Operations running any earlier Storm release are susceptible until a patch or mitigated configuration is applied.
Risk and Exploitability
With a CVSS score of 10, the exploitation risk is high. The EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalogue, suggesting that it may not yet be widely exploited publicly, yet the nature of the credential leak makes it attractive for malicious actors. Attackers can retrieve the payload by querying topology metadata or by accessing any log output where the payload was written, so the attack vector is likely remote through authenticated API calls or log aggregation systems. Once the credential is in hand, the attacker can modify cluster state via write‑capable Zookeeper ACLs, undermining topology integrity and availability.
OpenCVE Enrichment