Executive brief
Apache Storm is a distributed stream processing system used to process real-time data across clusters. A vulnerability in the topology submission mechanism allows authenticated users to read arbitrary files on the Nimbus server—including encryption keys, authentication credentials, and configuration files—without proper validation of the uploaded jar location. An attacker could obtain the Nimbus Kerberos keytab to escalate from a regular user to cluster administrator.
Technical details
The vulnerability is an inadequate path validation flaw in the `submitTopology` and `submitTopologyWithOpts` RPC methods. The Nimbus daemon accepts a server-side file path as the `uploadedJarLocation` parameter without verifying that the path refers to a file previously uploaded by the caller via `beginFileUpload`. An authenticated user can supply an arbitrary readable path (e.g., `/etc/passwd`, the Kerberos keytab, or TLS private keys) to the submission RPC. Nimbus then copies the specified file into the topology jar blob, and the blob ACL grants the submitter read access, allowing them to retrieve sensitive files via standard blob download RPCs. Attack requires authentication and topology submission rights, though these are granted to all authenticated principals by default when `nimbus.users` is unset. Patched in version 3.1.0 with path canonicalization and validation that submission paths must resolve inside the Nimbus inbox.
Affected products
- Apache Storm before 3.1.0
Timeline
- 2026-09-14: disclosed