Kestrel
대시보드로 돌아가기
CVE-2026-82437MEDIUM· 4.3MITRENVD대응게시일: 2026. 09. 14.수정일: 2026. 09. 14.CNA: security@apache.orgDeferred

Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemon logs those se

Auth

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
4.3medium

이론적 심각도 점수

EPSS

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

악용 경로
공격 벡터네트워크
공격 복잡도낮음
필요 권한낮음
사용자 상호작용불필요
범위불변
영향
기밀성 영향낮음
무결성 영향없음
가용성 영향없음
버전별 점수
CVSS 3.14.3MEDIUM· 악용성 2.8· 영향도 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

약점 (CWE)

  • CWE-862

    권한 검사 누락 — 접근 권한 확인 없이 기능/자원에 접근 허용.

상세 설명

Description

The Logviewer offers logs.users and logs.groups so operators can control who may read log content. For
daemon logs those settings were not applied: the access decision combined the "this is a daemon log" flag
with the authorizer result in a way that discarded the authorizer's answer whenever the flag was set, and
the daemon log page and download endpoints reached the handler without consulting an authorizer at all. Any
user able to pass the configured servlet filter could therefore read nimbus.log, supervisor.log and the
other daemon logs on every reachable node, which contain other tenants' topology names, owners and
configuration fragments.

The same advisory covers the log listing endpoints, which accepted a user argument and never applied it, so
/listLogs and /searchLogs returned every tenant's topology and worker log file names regardless of the
caller. That part is metadata only.

There was no configuration that closed either behaviour.

Mitigation

Upgrade to 3.1.0, where the daemon log paths evaluate the same configured user and group lists that the
worker log paths already used, and the listing endpoints filter by the requesting user.

Users who cannot upgrade immediately should place the Logviewer behind a reverse proxy that restricts the
daemon log endpoints, and should treat daemon log content as readable by any filter-authenticated user.

Credit

The ASF -- found using Claude agents to study the security of open-source projects, validated and reported by Apache Storm.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.