Insufficiently Protected Credentials Affecting org.apache.storm:storm-server package, versions [3.0.0,3.1.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.34% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHESTORM-20186811
  • published28 Sept 2026
  • disclosed14 Sept 2026
  • creditUnknown

Introduced: 14 Sep 2026

NewCVE-2026-82433  (opens in a new tab)
CWE-522  (opens in a new tab)

How to fix?

Upgrade org.apache.storm:storm-server to version 3.1.0 or higher.

Overview

org.apache.storm:storm-server is a distributed realtime computation system.

Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the getNimbusConf process. An attacker can obtain sensitive configuration data, including authentication payloads and keystore or truststore passwords, by making unauthorized requests to the affected endpoints. This is possible because the configuration is returned without redaction after only a user-level authorization check, and the UI endpoint /api/v1/cluster/configuration does not enforce per-user authorization, allowing any user able to pass ui.filter to access the full configuration.

Workaround

This vulnerability can be mitigated by placing the UI behind an authenticating reverse proxy that restricts access to /api/v1/cluster/configuration, and by rotating any exposed authentication payloads and passwords.

CVSS Base Scores

version 4.0
version 3.1