Executive brief
Apache Storm's Logviewer component manages access to system and application logs across distributed nodes. A vulnerability in the daemon log access controls allows any authenticated user to read sensitive daemon logs (nimbus.log, supervisor.log) and log file listings without proper authorization checks, potentially exposing other tenants' topology configurations, ownership details, and operational metadata.
Technical details
The vulnerability is an authorization bypass affecting Apache Storm's Logviewer daemon log endpoints. The root cause is faulty logic in the access decision handler: when processing daemon logs, the authorization result was discarded if the "is daemon log" flag was set, and certain endpoints (daemon log page and download) bypassed authorization checks entirely. An attacker with network access to a Logviewer instance and ability to pass the servlet filter can read /nimbus.log, /supervisor.log, and other daemon logs on all reachable nodes. Additionally, the /listLogs and /searchLogs endpoints accept but ignore the user parameter, exposing log file listings from all tenants. The vulnerability was fixed in version 3.1.0 by applying consistent user/group authorization checks to daemon log paths and filtering listing endpoints by requesting user.
Affected products
- Apache Storm before 3.1.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in Apache Storm 3.1.0