As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer
Apache Storm Logviewer versions 3.0.0 before 3.1.0 fail to enforce configured access controls on daemon logs, allowing unauthorized users to read restricted log content. The vulnerability stems from improper logic that combines daemon log detection with authorization results, effectively bypassing the `logs.users` and `logs.groups` access restrictions operators configure.
Why it matters: Storm operators using versions prior to 3.1.0 face information disclosure risk if they rely on log access controls to protect sensitive data in daemon logs; patching or upgrading to 3.1.0 is needed to restore intended access restrictions.
- Source published
- First seen by Cybersecurity Tracker