Executive brief
Apache Storm's topology configuration API exposes sensitive cluster credentials including ZooKeeper authentication tokens and TLS keystore passwords without proper redaction. Users with read-only access to topology configuration can retrieve credentials that should only be accessible to cluster administrators, potentially enabling attackers to escalate privileges or compromise cluster security infrastructure.
Technical details
The vulnerability exists in the getTopologyPageInfo API operation, which merges Nimbus daemon configuration with topology-specific configuration and returns the combined result without credential redaction in the topology_conf field. This merged configuration is then served verbatim by the Storm UI in the GET /api/v1/topology/{id} endpoint and related metrics endpoints. The exposed credentials include storm.zookeeper.auth.payload, Thrift/Netty/ZooKeeper TLS keystore and truststore passwords, and plugin keys containing secrets. Under SimpleACLAuthorizer, principals listed in topology.readonly.users or topology.readonly.groups can exploit this to read daemon credentials that are properly redacted by the getNimbusConf API and gated on stronger authorization checks. The attack requires read-only topology access, which is a lower privilege level than cluster administration.
Affected products
- Apache Storm before 3.1.0
Timeline
- 2026-09-14: disclosed: CVE-2026-84179 published
- 2026-09-14: patched: Fixed in Apache Storm 3.1.0