This is an automated email from the ASF dual-hosted git repository.
andor pushed a commit to branch website
in repository https://gitbox.apache.org/repos/asf/zookeeper.git
The following commit(s) were added to refs/heads/website by this push:
new c81b720e5 Updated security page with recent CVEs
c81b720e5 is described below
commit c81b720e5ca3186444de8e2791278e2c19cafed0
Author: Andor Molnar <[email protected]>
AuthorDate: Sat Mar 7 00:26:02 2026 +0000
Updated security page with recent CVEs
---
src/main/resources/markdown/security.md | 53 +++++++++++++++++++++++++++++++++
1 file changed, 53 insertions(+)
diff --git a/src/main/resources/markdown/security.md
b/src/main/resources/markdown/security.md
index b28279c08..6c55f74b4 100644
--- a/src/main/resources/markdown/security.md
+++ b/src/main/resources/markdown/security.md
@@ -30,6 +30,8 @@ their <a href="https://www.apache.org/security/">Web page</a>
for more informati
## Vulnerability reports
+* [CVE-2026-24308: Sensitive information disclosure in client configuration
handling](#CVE-2026-24308)
+* [CVE-2026-24281: Reverse-DNS fallback enables hostname verification bypass
in ZooKeeper ZKTrustManager](#CVE-2026-24281)
* [CVE-2025-58457: Insufficient Permission Check in AdminServer
Snapshot/Restore Commands](#CVE-2025-58457)
* [CVE-2024-51504: Authentication bypass with IP-based authentication in Admin
Server](#CVE-2024-51504)
* [CVE-2024-23944: Information disclosure in persistent watcher
handling](#CVE-2024-23944)
@@ -40,6 +42,57 @@ their <a href="https://www.apache.org/security/">Web
page</a> for more informati
* [CVE-2016-5017: Buffer overflow vulnerability in ZooKeeper C cli
shell](#CVE-2016-5017)
+<a name="CVE-2026-24308"></a>
+### CVE-2026-24308: Sensitive information disclosure in client configuration
handling
+
+Severity: important
+
+Affected versions:
+
+- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.4
+- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.5
+
+Description:
+
+Improper handling of configuration values in ZKConfig in Apache ZooKeeper
3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive
information stored in client configuration in the client's logfile.
Configuration values are exposed at INFO level logging rendering potential
production systems affected by the issue. Users are recommended to upgrade to
version 3.8.6 or 3.9.5 which fixes this issue.
+
+Credit:
+
+Youlong Chen <[email protected]> (reporter)
+
+References:
+
+https://zookeeper.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-24308
+
+
+<a name="CVE-2026-24281"></a>
+### CVE-2026-24281: Reverse-DNS fallback enables hostname verification bypass
in ZooKeeper ZKTrustManager
+
+Severity: important
+
+Affected versions:
+
+- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.4
+- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.5
+
+Description:
+
+Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse
DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof
PTR records to impersonate ZooKeeper servers or clients with a valid
certificate for the PTR name. It's important to note that attacker must present
a certificate which is trusted by ZKTrustManager which makes the attack vector
harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5,
which fixes this issue by [...]
+
+This issue is being tracked as ZOOKEEPER-4986
+
+Credit:
+
+Nikita Markevich <[email protected]> (reporter)
+
+References:
+
+https://zookeeper.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-24281
+https://issues.apache.org/jira/browse/ZOOKEEPER-4986
+
+
<a name="CVE-2025-58457"></a>
### CVE-2025-58457: Insufficient Permission Check in AdminServer
Snapshot/Restore Commands