ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 2 sources: “CVE-2026-82434: Apache Storm Nimbus and Client expose topology ZooKeeper credential to read-only users and logs” — merged summary and timeline →

Re: CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs

AI summary · glm-5.3

Follow-up on oss-security asks why CVE-2026-82434, Apache Storm ZooKeeper credential disclosure to read-only users and logs, lacks a severity rating.

Gabriel Ravier replied to the oss-security disclosure thread for CVE-2026-82434, which affects Apache Storm Nimbus and Apache Storm Client. The vulnerability involves disclosure of the topology ZooKeeper credential to read-only users and to logs. The reply questions whether the CVE was filed without a severity rating or if it is simply missing from the listing. No exploitation details or affected versions are provided in the post.

  • CVE-2026-82434 affects Apache Storm Nimbus and Apache Storm Client
  • Topology ZooKeeper credential exposed to read-only users and logs
  • Mailing list follow-up questions missing CVSS severity rating
  • No exploitation or PoC reported

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82434
Apache Storm Leaks ZooKeeper Topology Credential to Read-Only Users and Logs

Apache Storm's Nimbus server serves the full topology configuration — including the ZooKeeper credential stored in storm.zookeeper.topology.auth.payload — verbatim to any caller holding only read-only topology permissions, even though that credential is write-capable for the topology's worker heartbeats, backpressure, and error state (it is not a write credential on assignments). The same advisory covers the submission client, which logs the generated payload at INFO on every submission that generates one, and the SASL handlers, which log it at DEBUG, so the secret also reaches log aggregations and support bundles collected from the cluster. A low-privileged user who can merely view a topology, or anyone able to read cluster logs or support bundles, can obtain the credential and forge or delete that topology's worker state. Affected deployments are Apache Storm clusters running versions prior to 3.1.0 with ZooKeeper authentication configured. No public proof-of-concept or in-the-wild exploitation is known and the CVE is not on the CISA KEV list, despite a critical CVSS 4.0 score of 10.0.

Do: Upgrade to Apache Storm 3.1.0, where the payload is removed from the configuration served to read-only callers and is no longer written to logs. If you cannot upgrade immediately, rotate storm.zookeeper.topology.auth.payload for all existing topologies, review and scrub retained logs and support bundles for the credential value, and restrict read-only topology permissions to trusted principals only.

10.0
  • Apache Software Foundation Apache Storm (Nimbus) versions prior to 3.1.0
  • Apache Software Foundation Apache Storm Client (submission client and SASL handlers) versions prior to 3.1.0
nichelikely on the order of low thousands of cluster deployments worldwide (clearly an estimate)
Full article

Posted by Gabriel Ravier on Sep 13 This vulnerability was filed without a severity? Or is it missing from here?

This source does not provide full text. Read it at seclists.org.