以下是该漏洞描述的中文翻译: 描述 将 Nimbus 守护进程的配置与拓扑自身的配置进行了合并,并在 的 字段中返回了未脱敏的结果。Storm UI 将该值原封不动地复制到了 以及相应指标端点的 字段中。 如果集群中配置了这些项,合并后的映射将包含 (Storm 官方文档建议操作人员将其存放在 中,并设置权限以拒绝来自 Worker 的访问),以及用于 Thrift、Netty 和 ZooKeeper TLS 配置的密钥库(keystore)和信任库(truststore)密码,以及任何名称表明其为机密信息的插件密
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Storm Nimbus | 3.0.0 ~ 3.1.0 | - |
|
| Apache Software Foundation | Apache Storm UI | 3.0.0 ~ 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82434 | 10.0 CRITICAL | Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential |
| CVE-2026-78330 | Apache Syncope: Privilege escalation for admin user via JWT authentication | |
| CVE-2026-73579 | Apache Syncope: Non-recursive Any search could skip Realms restrictions | |
| CVE-2026-75015 | Apache Syncope: Nested secrets leak cleartext into audit records readable | |
| CVE-2026-75030 | Apache Syncope: Incomplete authorization checks for Group members deprovisioning | |
| CVE-2026-77051 | Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search | |
| CVE-2026-73668 | Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values | |
| CVE-2026-77147 | Apache Syncope: Groovy Sandbox escape for empty CommandArgs | |
| CVE-2026-77181 | Apache Syncope: ClientApp update entitlement not effective | |
| CVE-2026-77883 | Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBui | |
| CVE-2026-78318 | Apache Syncope: Unauthenticated reflected XSS in Console and Enduser | |
| CVE-2026-73470 | Apache Syncope: Delegating users can grant unowned Roles | |
| CVE-2026-78336 | Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user | |
| CVE-2026-82232 | Apache Syncope: SQL injection via sort parameter in Task search | |
| CVE-2026-86460 | Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence | |
| CVE-2026-87779 | Apache Syncope: AES Secret Key disclosure via log output | |
| CVE-2026-87785 | Apache Syncope: JWT subject spoofing | |
| CVE-2026-87802 | Apache Syncope: SRA OAuth2 JWT signature verification bypass | |
| CVE-2026-68570 | Apache Doris: Authorization bypass leading to unauthorized data access | |
| CVE-2026-72524 | Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitr |
Showing top 20 of 39 CVEs. View all on vendor page → →
No comments yet