Horizon Alert
Summary of the vulnerability and why it matters
This CVE involves Apache Storm, a system for processing data streams. It relates to how the system handles credentials, potentially exposing them to unauthorized viewing and allowing manipulation of cluster state for specific topologies. The main concern is confirming relevance and exposure.
- A credential leak could allow unauthorized access.
- Sensitive data exposure or state manipulation is possible.
- Confirm relevance and verify any exposure to sensitive data.
Attack Path
How an attacker could exploit the issue
An attacker could gain access to sensitive ZooKeeper credentials by exploiting a misconfiguration in Apache Storm's authentication handling. This occurs when Nimbus, the Storm scheduler, serves topology configurations containing ZooKeeper authentication details to any user with read-only permissions. Attackers who can view a topology's configuration, even without write access, can therefore obtain credentials that grant them write capabilities. These credentials could then be used to alter or delete topology state, such as heartbeats or backpressure information.
- Read-only topology access required.
- Nimbus serves sensitive credentials.
- Compromise topology state.
Live Threat
Current exploitation, exposure, and threat context
When ZooKeeper authentication is configured, a credential used to manage topology state could be exposed to unauthorized users who only have read-only access to view topology configurations. This exposure could occur if these users request topology information, leading to the credential being served to them verbatim. The credential is not read-only and may allow manipulation of topology state. Additionally, the credential could be logged and included in support bundles.
- Topology management credential.
- Served to read-only topology viewers.
- Topology state could be altered.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Apache Storm platform team and the application owners managing Storm topologies are likely responsible for addressing this vulnerability. The first practical step is to identify all deployed Storm clusters and topologies, confirm their exposure and criticality, and then determine the specific owners of those topologies to plan remediation.
- Owner: Platform and application owners.
- Verify: Topology reachability and criticality.
- Action: Plan coordinated upgrade or mitigation.