« Volver al listado

Apache

Apache Zookeeper: vulnerabilidades y CVE

Apache Zookeeper tiene 17 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE17
Últimos 12 meses8
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-84501Media (5.3)0.74%—16 sept 2026
An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name…
CVE-2026-84439Media (5.3)0.74%—16 sept 2026
When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t)…
CVE-2026-79993Alta (7.5)0.60%—16 sept 2026
The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL restrictions on the…
CVE-2026-59969Alta (7.5)0.33%—16 sept 2026
Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and…
CVE-2026-59739Alta (7.5)0.55%—16 sept 2026
Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can discover ACL-restricted paths by registering exists-watches on non-existent paths, then reconnecting…
CVE-2026-11746Crítica (9.4)0.23%—22 jun 2026
A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded,…
CVE-2026-24308Alta (7.5)1.2%—7 mar 2026
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile.…
CVE-2026-24281Alta (7.4)0.63%—7 mar 2026
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with…
CVE-2025-58457Media (4.3)0.32%—24 sept 2025
Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 before 3.9.4. Users are…
CVE-2024-51504Crítica (9.1)0.92%—7 nov 2024
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented in ZooKeeper Admin Server. Default…
CVE-2024-23944Media (5.3)0.25%—15 mar 2024
Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which…
CVE-2023-44981Crítica (9.1)1.7%—11 oct 2023
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that…
CVE-2021-21295Media (5.9)19%—9 mar 2021
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version…
CVE-2019-0201Media (5.9)9.7%—23 may 2019
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information…
CVE-2018-8012Alta (7.5)8.5%—21 may 2018
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and…
CVE-2017-5637Alta (7.5)73%—10 oct 2017
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache…
CVE-2016-5017Alta (8.1)7.9%—21 sept 2016
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application5
  2. T1078.001 Default Accounts1
  3. T1210 Exploitation of Remote Services1
  4. T1552.001 Credentials In Files1
  5. T1552.007 Container API1
  6. T1557 Adversary-in-the-Middle1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Apache