Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/Apache Software Foundation/org.apache.storm:storm-webapp

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-82433 is a vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. The getNimbusConf function returned the full daemon configuration without properly redacting sensitive credentials after only a user-level authorization check. The UI endpoint /api/v1/cluster/configuration lacked proper authorization checks, allowing any user passing the UI filter to access sensitive configuration data including passwords and authentication payloads. This exposure includes ZooKeeper authentication payloads and TLS keystore/truststore passwords. The issue was fixed in version 3.1.0 by masking credential-bearing values and enforcing explicit authorization on all UI API endpoints. Users unable to upgrade immediately should restrict access to the vulnerable endpoint via an authenticating reverse proxy and rotate exposed credentials.

Join the discussion

CVE-2026-82437 is a missing authorization vulnerability in Apache Storm Logviewer versions 3.0.0 up to but not including 3.1.0. The flaw allows any user who can pass the configured servlet filter to access daemon logs such as nimbus.log and supervisor.log on reachable nodes without proper authorization. Additionally, log listing endpoints exposed metadata about all tenants' topology and worker log files without filtering by user. There was no configuration to restrict this behavior prior to version 3.1.0.

Join the discussion

CVE-2026-82438 is an origin validation error in Apache Storm Webapp's HTTP components that allows web pages from unrelated origins to read responses intended for authenticated users. The vulnerability arises from three issues: the Logviewer reflecting the Origin header in Access-Control-Allow-Origin with credentials allowed, a misconfigured shared CORS filter permitting credentials, and JSONP wrapping of API responses without an option to disable it. These flaws enable cross-origin reading of cluster, topology, and log data by authenticated operators. The issue is fixed in Apache Storm 3.1.0 by correcting CORS handling and disabling JSONP by default. Users unable to upgrade immediately should use a reverse proxy to strip problematic headers and reject callback parameters.

Join the discussion

CVE-2026-84179 is a vulnerability in Apache Storm Nimbus versions 3.0.0 up to but not including 3.1.0. It involves insufficient protection of sensitive credentials in the Nimbus API, where the getTopologyPageInfo operation returns merged configuration data including sensitive credentials without redaction. This allows principals with read-only topology access to view sensitive daemon credentials such as ZooKeeper authentication payloads and TLS keystore passwords. The issue is fixed in version 3.1.0 by masking credential-bearing values before serving configuration data.

Join the discussion

Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping values directly into HTML via innerHTML in parseNode() and parseEdge() without sanitization at any layer. An authenticated user with topology submission rights could craft a topology containing malicious HTML/JavaScript in component identifiers (e.g., a bolt ID containing an onerror event handler). This payload flows through Nimbus → Thrift → the Visualization API → vis.js tooltip rendering, resulting in stored cross-site scripting.  In multi-tenant deployments where topology submission is available to less-trusted users but the UI is accessed by operators or administrators, this enables privilege escalation through script execution in an admin's browser session. Mitigation: 2.x users should upgrade to 2.8.6. Users who cannot upgrade immediately should monkey-patch the parseNode() and parseEdge() functions in the visualization JavaScript file to HTML-escape all API-supplied values including nodeId, :capacity, :latency, :component, :stream, and :grouping before interpolation into tooltip HTML strings, and should additionally restrict topology submission to trusted users via Nimbus ACLs as a defense-in-depth measure. A guide on how to do this is available in the release notes of 2.8.6. Credit: This issue was discovered while investigating another report by K.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:maven/Apache Software Foundation/org.apache.storm:storm-webapp
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses