Executive brief
Apache Storm is a distributed stream processing system used to process large volumes of data in real-time. An attacker with topology submission privileges could exploit a path traversal vulnerability in the blobstore configuration to delete arbitrary supervisor-owned files or create malicious symlinks that allow code execution as another user, bypassing the intended tenant isolation.
Technical details
The vulnerability exists in Storm's `AsyncLocalizer` and `Container.createBlobstoreLinks` components, which fail to normalize the `topology.blobstore.map` configuration. An attacker can craft a topology containing path traversal sequences (e.g., `../`) in blob names to direct delete-and-symlink operations at arbitrary paths on the supervisor node. Because the symlink creation forcibly deletes existing files before creating the link, an attacker can recursively delete supervisor-owned content or plant symlinks that cause subsequent worker processes to execute arbitrary code as a different tenant user. The attack requires topology submission privileges and affects all nodes where the topology is scheduled. A fix was released in version 3.1.0 that enforces path normalization checks at both call sites.
Affected products
- Apache Storm before 3.1.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fix available in version 3.1.0