Description
Description

getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field of TopologyPageInfo. The Storm UI copied that value verbatim into the configuration field of GET /api/v1/topology/{id} and of the corresponding metrics endpoint.

Where the cluster is configured with them, the merged map includes storm.zookeeper.auth.payload, which Storm's own documentation directs operators to keep in storm-cluster-auth.yaml under permissions that deny access from workers, together with the keystore and truststore passwords for the Thrift, Netty and ZooKeeper TLS configuration, and any plugin key whose name denotes a secret.

getTopologyPageInfo is a topology read-only operation. Under SimpleACLAuthorizer a principal listed in topology.readonly.users or topology.readonly.groups could therefore read daemon credentials that the dedicated cluster configuration API, getNimbusConf, redacts and that is gated on nimbus.users instead. The sibling operations that exist to serve configuration were masked; the topology page, which merges in strictly more daemon state, was not.

Mitigation

Upgrade to 3.1.0, where credential-bearing values are masked before any configuration is served over the Nimbus API.

Users who cannot upgrade immediately should remove any principal that is not trusted with cluster credentials from topology.readonly.users, topology.readonly.groups, topology.users and topology.groups, and should rotate the ZooKeeper authentication payload and any TLS keystore or truststore passwords that were reachable through the topology page.

Credit
Wanxin Yin (yaklang.io) reported this issue to the Apache Security Team.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of cluster credentials
Action: Immediate Patch
AI Analysis

Impact

The vulnerability, classified as CWE‑200 Information Exposure and CWE‑522 Insecure Credentials, enables an attacker with read‑only topology permissions to retrieve a merged configuration map that contains sensitive credentials such as the ZooKeeper authentication payload, keystore and truststore passwords, and other secret keys. This occurs because the getTopologyPageInfo function concatenates Nimbus daemon configuration with the topology configuration and returns the result without redaction, and the UI surface copies that data verbatim into several API responses. The result is a leakage of confidential data to unauthorized parties, violating cluster confidentiality.

Affected Systems

All Apache Storm installations using Nimbus or Storm UI at versions prior to 3.1.0 are affected. The affected components include Apache Storm Nimbus and the Storm UI web interface. The 3.1.0 release introduces masking of credential‑bearing values before the configuration is served over the Nimbus API.

Risk and Exploitability

The vulnerability is accessed via the read‑only topology endpoint (GET /api/v1/topology/{id}) which can be invoked by principals listed in topology.readonly.users or topology.readonly.groups, with a CVSS score of 6.5. As the attack vector is over a standard HTTP API and the attacker requires only read‑only topology permissions, the confidentiality risk is significant. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but the potential impact on cluster credentials warrants prompt remediation.

Generated by OpenCVE AI on September 21, 2026 at 00:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache Storm 3.1.0, where credential‑bearing values are masked before being served over the Nimbus API.
  • If an upgrade cannot be performed immediately, remove any untrusted principals from topology.readonly.users, topology.readonly.groups, topology.users, and topology.groups to limit read‑only access.
  • Rotate the ZooKeeper authentication payload and any TLS keystore or truststore passwords that were revealed through the topology page to invalidate compromised credentials.

Generated by OpenCVE AI on September 21, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field of TopologyPageInfo. The Storm UI copied that value verbatim into the configuration field of GET /api/v1/topology/{id} and of the corresponding metrics endpoint. Where the cluster is configured with them, the merged map includes storm.zookeeper.auth.payload, which Storm's own documentation directs operators to keep in storm-cluster-auth.yaml under permissions that deny access from workers, together with the keystore and truststore passwords for the Thrift, Netty and ZooKeeper TLS configuration, and any plugin key whose name denotes a secret. getTopologyPageInfo is a topology read-only operation. Under SimpleACLAuthorizer a principal listed in topology.readonly.users or topology.readonly.groups could therefore read daemon credentials that the dedicated cluster configuration API, getNimbusConf, redacts and that is gated on nimbus.users instead. The sibling operations that exist to serve configuration were masked; the topology page, which merges in strictly more daemon state, was not. Mitigation Upgrade to 3.1.0, where credential-bearing values are masked before any configuration is served over the Nimbus API. Users who cannot upgrade immediately should remove any principal that is not trusted with cluster credentials from topology.readonly.users, topology.readonly.groups, topology.users and topology.groups, and should rotate the ZooKeeper authentication payload and any TLS keystore or truststore passwords that were reachable through the topology page. Credit Wanxin Yin (yaklang.io) reported this issue to the Apache Security Team.
Title Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page
Weaknesses CWE-200
CWE-522
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:49:29.948Z

Reserved: 2026-09-01T09:25:56.223Z

Link: CVE-2026-84179

cve-icon Vulnrichment

Updated: 2026-09-14T14:13:50.503Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:13.130

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-84179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:30:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-522

    Insufficiently Protected Credentials