Impact
The Logviewer component of Apache Storm implements access controls for user and group based log reading. However, for daemon logs the access decision mistakenly drops the authorization check whenever the "daemon log" flag is set, and the corresponding endpoints bypass the authorizer entirely. As a result, any entity able to satisfy the servlet filter can read the content of logs such as nimbus.log, supervisor.log, and other system logs. In addition, the log listing endpoints accept user input but ignore it, returning the full set of tenant log file names to every caller. These are purely metadata, but combined with the raw log data expose detailed configuration fragments and topology names missing or incorrectly applied authorization validation (CWE‑862).
Affected Systems
Apache Software Foundation: Apache Storm Logviewer. All deployments using the Logviewer component prior to version 3.1.0 are affected. The specific affected code paths are the daemon log page and download handlers, as well as the /listLogs and /searchLogs endpoints. No version matrix is provided beyond the recommendation to upgrade, so any installation of the Logviewer that includes daemon log handling is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is <1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is any user who can reach the Logviewer service and satisfy the servlet filter, which may include remotely reachable clients or internal actors. The absence of a configuration knob to disable the exposed behavior means the risk remains unless mitigated by patching or additional network controls.
OpenCVE Enrichment