CVE-2026-84179: CWE-522: Insufficiently Protected Credentials in Apache Software Foundation Apache Storm Nimbus
CVE-2026-84179 is a vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It involves insufficient protection of sensitive credentials in the Nimbus API, where the getTopologyPageInfo operation returns merged configuration data including sensitive credentials without redaction. This allows principals with read-only topology access to view sensitive daemon credentials such as ZooKeeper authentication payloads and TLS keystore passwords. The issue is fixed in version 3.1.0 by masking credential-bearing values before serving configuration data.
AI Analysis
Technical Summary
The vulnerability arises because the getTopologyPageInfo API call merges the Nimbus daemon configuration with the topology's configuration and returns it without redacting sensitive credential information in the topology_conf field. This includes sensitive data such as storm.zookeeper.auth.payload, TLS keystore and truststore passwords, and plugin keys marked as secrets. Under the SimpleACLAuthorizer, users with read-only topology access (topology.readonly.users or topology.readonly.groups) can access these credentials, bypassing the more restrictive access controls applied to the dedicated cluster configuration API getNimbusConf. The vulnerability is addressed in Apache Storm Nimbus 3.1.0 by masking credential-bearing values before any configuration is served via the Nimbus API.
Potential Impact
Unauthorized users with read-only topology access can obtain sensitive cluster credentials, including ZooKeeper authentication payloads and TLS keystore/truststore passwords. This exposure could lead to compromise of cluster security and unauthorized access to protected resources. The vulnerability does not require elevated privileges beyond read-only topology access but exposes highly sensitive configuration data.
Mitigation Recommendations
Upgrade to Apache Storm Nimbus version 3.1.0 or later, where credential-bearing values are masked before configuration data is served via the Nimbus API. For users unable to upgrade immediately, remove any principals not fully trusted with cluster credentials from topology.readonly.users, topology.readonly.groups, topology.users, and topology.groups. Additionally, rotate the ZooKeeper authentication payload and any TLS keystore or truststore passwords that may have been exposed through the topology page.
CVE-2026-84179: CWE-522: Insufficiently Protected Credentials in Apache Software Foundation Apache Storm Nimbus
Description
CVE-2026-84179 is a vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It involves insufficient protection of sensitive credentials in the Nimbus API, where the getTopologyPageInfo operation returns merged configuration data including sensitive credentials without redaction. This allows principals with read-only topology access to view sensitive daemon credentials such as ZooKeeper authentication payloads and TLS keystore passwords. The issue is fixed in version 3.1.0 by masking credential-bearing values before serving configuration data.
Affected software
Apache Software Foundation
Apache Storm Nimbus
Apache Software Foundation
Apache Storm UI
pkg:maven/Apache Software Foundation/org.apache.storm:storm-serverpkg:maven/Apache Software Foundation/org.apache.storm:storm-webappRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because the getTopologyPageInfo API call merges the Nimbus daemon configuration with the topology's configuration and returns it without redacting sensitive credential information in the topology_conf field. This includes sensitive data such as storm.zookeeper.auth.payload, TLS keystore and truststore passwords, and plugin keys marked as secrets. Under the SimpleACLAuthorizer, users with read-only topology access (topology.readonly.users or topology.readonly.groups) can access these credentials, bypassing the more restrictive access controls applied to the dedicated cluster configuration API getNimbusConf. The vulnerability is addressed in Apache Storm Nimbus 3.1.0 by masking credential-bearing values before any configuration is served via the Nimbus API.
Potential Impact
Unauthorized users with read-only topology access can obtain sensitive cluster credentials, including ZooKeeper authentication payloads and TLS keystore/truststore passwords. This exposure could lead to compromise of cluster security and unauthorized access to protected resources. The vulnerability does not require elevated privileges beyond read-only topology access but exposes highly sensitive configuration data.
Mitigation Recommendations
Upgrade to Apache Storm Nimbus version 3.1.0 or later, where credential-bearing values are masked before configuration data is served via the Nimbus API. For users unable to upgrade immediately, remove any principals not fully trusted with cluster credentials from topology.readonly.users, topology.readonly.groups, topology.users, and topology.groups. Additionally, rotate the ZooKeeper authentication payload and any TLS keystore or truststore passwords that may have been exposed through the topology page.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-09-01T09:25:56.223Z
- State
- PUBLISHED
Threat ID: 6aa8057455bf5e2cf52f81d0
Added to database: 09/14/2026, 14:32:20 UTC
Last enriched: 09/14/2026, 14:47:15 UTC
Last updated: 09/14/2026, 14:47:15 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.