This is an automated email from the ASF dual-hosted git repository.

andor pushed a commit to branch website
in repository https://gitbox.apache.org/repos/asf/zookeeper.git


The following commit(s) were added to refs/heads/website by this push:
     new c81b720e5 Updated security page with recent CVEs
c81b720e5 is described below

commit c81b720e5ca3186444de8e2791278e2c19cafed0
Author: Andor Molnar <[email protected]>
AuthorDate: Sat Mar 7 00:26:02 2026 +0000

    Updated security page with recent CVEs
---
 src/main/resources/markdown/security.md | 53 +++++++++++++++++++++++++++++++++
 1 file changed, 53 insertions(+)

diff --git a/src/main/resources/markdown/security.md 
b/src/main/resources/markdown/security.md
index b28279c08..6c55f74b4 100644
--- a/src/main/resources/markdown/security.md
+++ b/src/main/resources/markdown/security.md
@@ -30,6 +30,8 @@ their <a href="https://www.apache.org/security/";>Web page</a> 
for more informati
 
 ## Vulnerability reports
 
+* [CVE-2026-24308: Sensitive information disclosure in client configuration 
handling](#CVE-2026-24308)
+* [CVE-2026-24281: Reverse-DNS fallback enables hostname verification bypass 
in ZooKeeper ZKTrustManager](#CVE-2026-24281)
 * [CVE-2025-58457: Insufficient Permission Check in AdminServer 
Snapshot/Restore Commands](#CVE-2025-58457)
 * [CVE-2024-51504: Authentication bypass with IP-based authentication in Admin 
Server](#CVE-2024-51504)
 * [CVE-2024-23944: Information disclosure in persistent watcher 
handling](#CVE-2024-23944)
@@ -40,6 +42,57 @@ their <a href="https://www.apache.org/security/";>Web 
page</a> for more informati
 * [CVE-2016-5017: Buffer overflow vulnerability in ZooKeeper C cli 
shell](#CVE-2016-5017)
 
 
+<a name="CVE-2026-24308"></a>
+### CVE-2026-24308: Sensitive information disclosure in client configuration 
handling
+
+Severity: important
+
+Affected versions:
+
+- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.4
+- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.5
+
+Description:
+
+Improper handling of configuration values in ZKConfig in Apache ZooKeeper 
3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive 
information stored in client configuration in the client's logfile. 
Configuration values are exposed at INFO level logging rendering potential 
production systems affected by the issue. Users are recommended to upgrade to 
version 3.8.6 or 3.9.5 which fixes this issue.
+
+Credit:
+
+Youlong Chen <[email protected]> (reporter)
+
+References:
+
+https://zookeeper.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-24308
+
+
+<a name="CVE-2026-24281"></a>
+### CVE-2026-24281: Reverse-DNS fallback enables hostname verification bypass 
in ZooKeeper ZKTrustManager
+
+Severity: important
+
+Affected versions:
+
+- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.4
+- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.5
+
+Description:
+
+Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse 
DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof 
PTR records to impersonate ZooKeeper servers or clients with a valid 
certificate for the PTR name. It's important to note that attacker must present 
a certificate which is trusted by ZKTrustManager which makes the attack vector 
harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, 
which fixes this issue by  [...]
+
+This issue is being tracked as ZOOKEEPER-4986
+
+Credit:
+
+Nikita Markevich <[email protected]> (reporter)
+
+References:
+
+https://zookeeper.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-24281
+https://issues.apache.org/jira/browse/ZOOKEEPER-4986
+
+
 <a name="CVE-2025-58457"></a>
 ### CVE-2025-58457: Insufficient Permission Check in AdminServer 
Snapshot/Restore Commands
 

Reply via email to