Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability impacts Apache Storm's Nimbus component, which is responsible for managing cluster topologies. It allows an attacker to potentially delete critical files or disrupt cluster operations by submitting a specially crafted topology. The primary concern is confirming if this technology is in use within your environment and understanding any potential exposure.
- Allows malicious topology submissions.
- Critical for cluster stability and operations.
- Confirm usage and assess potential impact.
Attack Path
How an attacker could exploit the issue
An attacker can interfere with the cluster's leadership by manipulating topology submissions. By providing a crafted list of blobstore keys, an attacker can cause existing topologies to be deleted or prevent Nimbus servers from maintaining leadership, leading to cluster instability.
- Topology submission with malicious keys.
- Nimbus processes invalid dependency keys.
- Cluster instability and unavailability.
Live Threat
Current exploitation, exposure, and threat context
A submitted topology can contain lists of blobstore keys that Nimbus, the topology manager, does not validate. When Nimbus cleans up a finished topology, it deletes the blobstore keys provided. An attacker could list a key belonging to another topology, causing that blob to be deleted during cleanup. Additionally, when Nimbus attempts to acquire leadership, it compares active topology dependency keys against blobstore contents. A single missing key could cause all Nimbus instances to repeatedly acquire and surrender leadership, leading to cluster instability and preventing the scheduling or cleanup of topologies.
- Blobstore keys, topology artifacts, cluster leadership.
- Malformed topology submission.
- Cluster instability, topology management failure.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Nimbus component of Apache Storm is responsible for managing cluster topologies. The platform or infrastructure team typically owns the Nimbus deployment. If a cluster is experiencing leadership issues, they should first investigate Nimbus logs for missing dependency keys to identify affected topologies. Coordination with application owners or the security team may be necessary to plan remediation.
- Platform/Infrastructure owns the issue.
- Verify cluster leadership and Nimbus logs.
- Plan topology resubmission or removal.