Impact
The vulnerability, classified as CWE‑200 Information Exposure and CWE‑522 Insecure Credentials, enables an attacker with read‑only topology permissions to retrieve a merged configuration map that contains sensitive credentials such as the ZooKeeper authentication payload, keystore and truststore passwords, and other secret keys. This occurs because the getTopologyPageInfo function concatenates Nimbus daemon configuration with the topology configuration and returns the result without redaction, and the UI surface copies that data verbatim into several API responses. The result is a leakage of confidential data to unauthorized parties, violating cluster confidentiality.
Affected Systems
All Apache Storm installations using Nimbus or Storm UI at versions prior to 3.1.0 are affected. The affected components include Apache Storm Nimbus and the Storm UI web interface. The 3.1.0 release introduces masking of credential‑bearing values before the configuration is served over the Nimbus API.
Risk and Exploitability
The vulnerability is accessed via the read‑only topology endpoint (GET /api/v1/topology/{id}) which can be invoked by principals listed in topology.readonly.users or topology.readonly.groups, with a CVSS score of 6.5. As the attack vector is over a standard HTTP API and the attacker requires only read‑only topology permissions, the confidentiality risk is significant. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but the potential impact on cluster credentials warrants prompt remediation.
OpenCVE Enrichment