以下是该漏洞描述的中文翻译: 描述 当配置了 ZooKeeper 认证时,Apache Storm 会刻意在拓扑配置中保留 ,因为 Worker 节点需要它。Nimbus 随后会将该配置原样发送给任何拥有只读拓扑权限的调用者,这意味着一个仅拥有查看拓扑权限的用户也能获取到该 ZooKeeper 凭据。 该凭据并非只读。集群状态实现使用具有写权限的 ACL(访问控制列表)用于 Worker 心跳、背压机制和错误状态,因此接收到该凭据的用户可以伪造或删除相应拓扑的集群状态。需要注意的是,该凭据并非用于分配(assign
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Storm Nimbus | 3.0.0 ~ 3.1.0 | - |
|
| Apache Software Foundation | Apache Storm Client | 3.0.0 ~ 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78330 | Apache Syncope: Privilege escalation for admin user via JWT authentication | |
| CVE-2026-73579 | Apache Syncope: Non-recursive Any search could skip Realms restrictions | |
| CVE-2026-75015 | Apache Syncope: Nested secrets leak cleartext into audit records readable | |
| CVE-2026-75030 | Apache Syncope: Incomplete authorization checks for Group members deprovisioning | |
| CVE-2026-77051 | Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search | |
| CVE-2026-73668 | Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values | |
| CVE-2026-77147 | Apache Syncope: Groovy Sandbox escape for empty CommandArgs | |
| CVE-2026-77181 | Apache Syncope: ClientApp update entitlement not effective | |
| CVE-2026-77883 | Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBui | |
| CVE-2026-78318 | Apache Syncope: Unauthenticated reflected XSS in Console and Enduser | |
| CVE-2026-73470 | Apache Syncope: Delegating users can grant unowned Roles | |
| CVE-2026-78336 | Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user | |
| CVE-2026-82232 | Apache Syncope: SQL injection via sort parameter in Task search | |
| CVE-2026-86460 | Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence | |
| CVE-2026-87779 | Apache Syncope: AES Secret Key disclosure via log output | |
| CVE-2026-87785 | Apache Syncope: JWT subject spoofing | |
| CVE-2026-87802 | Apache Syncope: SRA OAuth2 JWT signature verification bypass | |
| CVE-2026-68570 | Apache Doris: Authorization bypass leading to unauthorized data access | |
| CVE-2026-72524 | Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitr | |
| CVE-2026-82438 | Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins |
Showing top 20 of 39 CVEs. View all on vendor page → →
No comments yet