Description
Description

Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP
components served to an authenticated user.

The Logviewer reflected the request's `Origin` header back in `Access-Control-Allow-Origin` while also
sending `Access-Control-Allow-Credentials: true`. The published security model documents a permissive
`Access-Control-Allow-Origin: *` posture as accepted, which is safe precisely because browsers refuse to
honour `*` together with credentials; reflecting the concrete origin removes that protection.

The shared CORS filter used by the UI, the Logviewer and DRPC was configured with a response header name
where an initialisation parameter name was expected. The container ignored the setting and applied its own
defaults, which allow credentials.

Finally, the UI and Logviewer wrapped API responses in a caller-supplied JSONP callback for every GET
request. A script element on any origin can load such a response, which bypasses the same-origin policy
entirely rather than negotiating it, and there was no way to turn the behaviour off.

In each case the effect is that a page visited by an authenticated operator can read cluster, topology and
log data on their behalf.

Mitigation

Upgrade to 3.1.0, where the Logviewer no longer reflects the request origin in a credentialed response, the
CORS filter is configured explicitly, and JSONP wrapping is governed by `ui.enable.jsonp`, which defaults to
false.

Note that disabling JSONP is a behaviour change for tooling that passes a `callback` query parameter; such
tooling should be moved to ordinary JSON requests.

Users who cannot upgrade immediately should place the UI, Logviewer and DRPC HTTP endpoints behind a reverse
proxy that strips `Access-Control-Allow-Origin` and `Access-Control-Allow-Credentials` from responses and
rejects requests carrying a `callback` parameter.

Credit

The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Published: 2026-09-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure via Cross‑Origin Access
Action: Upgrade
AI Analysis

Impact

Three distinct mechanisms allowed a web page on an unrelated origin to read responses that Storm’s HTTP components served to an authenticated user. One mechanism involved the Logviewer reflecting the request’s Origin header back in an Access‑Control‑Allow‑Origin header while also sending Access‑Control‑Allow‑Credentials: true. The default model documents a permissive Access‑Control‑Allow‑Origin: * posture that is safe only because browsers ignore * when credentials are present; reflecting a concrete origin removes that protection. Another mechanism was a shared CORS filter that expected an initialization parameter name but ignored it, allowing the container to apply defaults that enable credentials. The third mechanism was ubiquitous JSONP wrapping of every GET request – a script element can load such a response from any origin, bypassing the same‑origin policy entirely. In each case the effect is that an authenticated operator’s browser can read cluster, topology, and log data on their behalf, exposing sensitive internal information.

Affected Systems

The vulnerability affects Apache Storm Webapp deployments that have not been patched to version 3.1.0. Prior releases, such as those using the Logviewer and UI components with the legacy CORS and JSONP configuration, are susceptible.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity with significant impact on confidentiality, integrity, and availability of sensitive system data. The EPSS score of less than 1% suggests that, at the time of publication, the exploitation probability is very low, and the vulnerability is not yet listed in the CISA KEV catalog. Likely attack conditions require a malicious web page to be accessed by an authenticated operator who is actively using the Storm UI, UI Logviewer, or DRPC services. Because the exploitation path is web‑browser based and does not require privileged network access, the vulnerability is considered moderately exploitable, but attackers may need to entice an authenticated user to visit a crafted site.

Generated by OpenCVE AI on September 21, 2026 at 00:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Storm Webapp to version 3.1.0 or later, which removes the Origin‑reflection bug, configures the CORS filter properly, and disables JSONP wrapping by default.
  • If the application cannot be upgraded immediately, configure the UI, Logviewer, and DRPC HTTP endpoints behind a reverse proxy that strips the Access‑Control‑Allow‑Origin and Access‑Control‑Allow‑Credentials headers from responses and rejects any request containing a callback query parameter.
  • Ensure that JSONP is disabled in the configuration by setting ui.enable.jsonp to false, and test that “callback” parameters no longer influence the response format.
  • Verify that the CORS filter is configured to use Access‑Control‑Allow‑Origin: * without allowing credentials, matching the security model and preventing unauthorized cross‑origin reads.

Generated by OpenCVE AI on September 21, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Control-Allow-Origin` while also sending `Access-Control-Allow-Credentials: true`. The published security model documents a permissive `Access-Control-Allow-Origin: *` posture as accepted, which is safe precisely because browsers refuse to honour `*` together with credentials; reflecting the concrete origin removes that protection. The shared CORS filter used by the UI, the Logviewer and DRPC was configured with a response header name where an initialisation parameter name was expected. The container ignored the setting and applied its own defaults, which allow credentials. Finally, the UI and Logviewer wrapped API responses in a caller-supplied JSONP callback for every GET request. A script element on any origin can load such a response, which bypasses the same-origin policy entirely rather than negotiating it, and there was no way to turn the behaviour off. In each case the effect is that a page visited by an authenticated operator can read cluster, topology and log data on their behalf. Mitigation Upgrade to 3.1.0, where the Logviewer no longer reflects the request origin in a credentialed response, the CORS filter is configured explicitly, and JSONP wrapping is governed by `ui.enable.jsonp`, which defaults to false. Note that disabling JSONP is a behaviour change for tooling that passes a `callback` query parameter; such tooling should be moved to ordinary JSON requests. Users who cannot upgrade immediately should place the UI, Logviewer and DRPC HTTP endpoints behind a reverse proxy that strips `Access-Control-Allow-Origin` and `Access-Control-Allow-Credentials` from responses and rejects requests carrying a `callback` parameter. Credit The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.
Title Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins
Weaknesses CWE-346
CWE-942
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:52:48.724Z

Reserved: 2026-08-29T10:37:41.671Z

Link: CVE-2026-82438

cve-icon Vulnrichment

Updated: 2026-09-14T14:13:42.629Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:10.900

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-82438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-942

    Permissive Cross-domain Security Policy with Untrusted Domains