This is an automated email from the ASF dual-hosted git repository.
andor pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/zookeeper.git
The following commit(s) were added to refs/heads/asf-site by this push:
new 304651d03 Updated security page with recent CVEs
304651d03 is described below
commit 304651d03c14666d18ca618300540464a4f7addc
Author: Andor Molnar <[email protected]>
AuthorDate: Sat Mar 7 00:32:00 2026 +0000
Updated security page with recent CVEs
---
content/security.html | 39 +++++++++++++++++++++++++++++++++++----
1 file changed, 35 insertions(+), 4 deletions(-)
diff --git a/content/security.html b/content/security.html
index 85d3598c5..91744fc11 100644
--- a/content/security.html
+++ b/content/security.html
@@ -95,6 +95,8 @@ <h1>ZooKeeper Security</h1>
<p>The ASF Security team maintains a page with a description of how
vulnerabilities are handled, check their <a
href="https://www.apache.org/security/">Web page</a> for more information.</p>
<h2>Vulnerability reports</h2>
<ul>
+<li><a href="#CVE-2026-24308">CVE-2026-24308: Sensitive information disclosure
in client configuration handling</a></li>
+<li><a href="#CVE-2026-24281">CVE-2026-24281: Reverse-DNS fallback enables
hostname verification bypass in ZooKeeper ZKTrustManager</a></li>
<li><a href="#CVE-2025-58457">CVE-2025-58457: Insufficient Permission Check in
AdminServer Snapshot/Restore Commands</a></li>
<li><a href="#CVE-2024-51504">CVE-2024-51504: Authentication bypass with
IP-based authentication in Admin Server</a></li>
<li><a href="#CVE-2024-23944">CVE-2024-23944: Information disclosure in
persistent watcher handling</a></li>
@@ -104,6 +106,35 @@ <h2>Vulnerability reports</h2>
<li><a href="#CVE-2017-5637">CVE-2017-5637: DOS attack on wchp/wchc four
letter words (4lw)</a></li>
<li><a href="#CVE-2016-5017">CVE-2016-5017: Buffer overflow vulnerability in
ZooKeeper C cli shell</a></li>
</ul>
+<p><a name="CVE-2026-24308"></a></p>
+<h3>CVE-2026-24308: Sensitive information disclosure in client configuration
handling</h3>
+<p>Severity: important</p>
+<p>Affected versions:</p>
+<ul>
+<li>Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.4</li>
+<li>Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.5</li>
+</ul>
+<p>Description:</p>
+<p>Improper handling of configuration values in ZKConfig in Apache ZooKeeper
3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive
information stored in client configuration in the client's logfile.
Configuration values are exposed at INFO level logging rendering potential
production systems affected by the issue. Users are recommended to upgrade to
version 3.8.6 or 3.9.5 which fixes this issue.</p>
+<p>Credit:</p>
+<p>Youlong Chen <a
href="mailto:chenyoulong20g@ict.ac.cn">chenyoulong20g@ict.ac.cn</a>
(reporter)</p>
+<p>References:</p>
+<p>https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-24308</p>
+<p><a name="CVE-2026-24281"></a></p>
+<h3>CVE-2026-24281: Reverse-DNS fallback enables hostname verification bypass
in ZooKeeper ZKTrustManager</h3>
+<p>Severity: important</p>
+<p>Affected versions:</p>
+<ul>
+<li>Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.4</li>
+<li>Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.5</li>
+</ul>
+<p>Description:</p>
+<p>Hostname verification in Apache ZooKeeper ZKTrustManager falls back to
reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control
or spoof PTR records to impersonate ZooKeeper servers or clients with a valid
certificate for the PTR name. It's important to note that attacker must present
a certificate which is trusted by ZKTrustManager which makes the attack vector
harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5,
which fixes this issue [...]
+<p>This issue is being tracked as ZOOKEEPER-4986</p>
+<p>Credit:</p>
+<p>Nikita Markevich <a
href="mailto:markevich.nikita1@gmail.com">markevich.nikita1@gmail.com</a>
(reporter)</p>
+<p>References:</p>
+<p>https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-24281
https://issues.apache.org/jira/browse/ZOOKEEPER-4986</p>
<p><a name="CVE-2025-58457"></a></p>
<h3>CVE-2025-58457: Insufficient Permission Check in AdminServer
Snapshot/Restore Commands</h3>
<p>Severity: moderate</p>
@@ -117,7 +148,7 @@ <h3>CVE-2025-58457: Insufficient Permission Check in
AdminServer Snapshot/Restor
<p>Users are recommended to upgrade to version 3.9.4, which fixes the
issue.</p>
<p>The issue can be mitigated by disabling both commands (via
<code>admin.snapshot.enabled</code> and <code>admin.restore.enabled</code>),
disabling the whole AdminServer interface (via
<code>admin.enableServer</code>), or ensuring that the root ACL does not
provide open permissions. (Note that ZooKeeper ACLs are not recursive, so this
does not impact operations on child nodes besides notifications from recursive
watches.)</p>
<p>Credit:</p>
-<p>Damien Diederen <a
href="mailto:ddiederen@apache.org">ddiederen@apache.org</a>
(reporter)</p>
+<p>Damien Diederen <a
href="mailto:ddiederen@apache.org">ddiederen@apache.org</a>
(reporter)</p>
<p>References:</p>
<p><a href="https://zookeeper.apache.org/">https://zookeeper.apache.org/</a>
<a
href="https://www.cve.org/CVERecord?id=CVE-2025-58457">https://www.cve.org/CVERecord?id=CVE-2025-58457</a></p>
<p><a name="CVE-2024-51504"></a></p>
@@ -146,7 +177,7 @@ <h3>CVE-2024-23944: Information disclosure in persistent
watcher handling</h3>
<p>Information disclosure in persistent watchers handling in Apache ZooKeeper
due to missing ACL check. It allows an attacker to monitor child znodes by
attaching a persistent watcher (addWatch command) to a parent which the
attacker has already access to. ZooKeeper server doesn't do ACL check when the
persistent watcher is triggered and as a consequence, the full path of znodes
that a watch event gets triggered upon is exposed to the owner of the watcher.
It's important to note that onl [...]
<p>Users are recommended to upgrade to version 3.9.2, 3.8.4 which fixes the
issue.</p>
<p>Credit:</p>
-<p>周吉安(寒泉) <a
href="mailto:zhoujian.zja@alibaba-inc.com">zhoujian.zja@alibaba-inc.com</a>
(reporter)</p>
+<p>周吉安(寒泉) <a
href="mailto:zhoujian.zja@alibaba-inc.com">zhoujian.zja@alibaba-inc.com</a>
(reporter)</p>
<p>References:</p>
<p><a href="https://zookeeper.apache.org/">https://zookeeper.apache.org/</a>
<a
href="https://www.cve.org/CVERecord?id=CVE-2024-23944">https://www.cve.org/CVERecord?id=CVE-2024-23944</a></p>
<p><a name="CVE-2023-44981"></a></p>
@@ -165,7 +196,7 @@ <h3>CVE-2023-44981: Authorization bypass in SASL Quorum
Peer Authentication</h3>
<p>Alternately ensure the ensemble election/quorum communication is protected
by a firewall as this will mitigate the issue.</p>
<p>See the documentation for more details on correct cluster
administration.</p>
<p>Credit:</p>
-<p>Damien Diederen <a
href="mailto:ddiederen@apache.org">ddiederen@apache.org</a>
(reporter)</p>
+<p>Damien Diederen <a
href="mailto:ddiederen@apache.org">ddiederen@apache.org</a>
(reporter)</p>
<p>References:</p>
<p><a
href="https://zookeeper.apache.org/">https://zookeeper.apache.org/</a></p>
<p><a
href="https://www.cve.org/CVERecord?id=CVE-2023-44981">https://www.cve.org/CVERecord?id=CVE-2023-44981</a></p>
@@ -176,7 +207,7 @@ <h3>CVE-2019-0201: Information disclosure vulnerability in
Apache ZooKeeper</h3>
<p>Versions Affected: ZooKeeper prior to 3.4.14 ZooKeeper 3.5.0-alpha through
3.5.4-beta. The unsupported ZooKeeper 1.x through 3.3.x versions may be also
affected.</p>
<p>Description: ZooKeeper’s getACL() command doesn’t check any permission when
retrieves the ACLs of the requested node and returns all information contained
in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads
the Id field with the hash value that is used for user authentication. As a
consequence, if Digest Authentication is in use, the unsalted hash value will
be disclosed by getACL() request for unauthenticated or unprivileged users.</p>
<p>Mitigation: Use an authentication method other than Digest (e.g. Kerberos)
or upgrade to 3.4.14 or later (3.5.5 or later if on the 3.5 branch).</p>
-<p>Credit: This issue was identified by Harrison Neal <a
href="mailto:harrison@patchadvisor.com">harrison@patchadvisor.com</a>
PatchAdvisor, Inc.</p>
+<p>Credit: This issue was identified by Harrison Neal <a
href="mailto:harrison@patchadvisor.com">harrison@patchadvisor.com</a>
PatchAdvisor, Inc.</p>
<p>References: https://issues.apache.org/jira/browse/ZOOKEEPER-1392</p>
<p><a name="CVE-2018-8012"></a></p>
<h3>CVE-2018-8012: Apache ZooKeeper Quorum Peer mutual authentication</h3>