threat
engine
.sh
Back
·
··:··
Home
/
Product
/
apache zookeeper
Product
apache zookeeper
11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-24308
>= 3.8.0 and < 3.8.6
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to e
7.5
HIGH
CVE-2026-24281
>= 3.8.0 and < 3.8.6
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing at
7.4
HIGH
CVE-2025-58457
>= 3.9.0 and < 3.9.4
Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient p
4.3
MEDIUM
CVE-2024-51504
>= 3.9.0 and < 3.9.3
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this
9.1
CRITICAL
CVE-2024-23944
>= 3.6.0 and <= 3.7.2
Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to moni
5.3
MEDIUM
CVE-2023-44981
< 3.7.2
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled
9.1
CRITICAL
CVE-2021-21295
all versions
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high perfor
5.9
MEDIUM
CVE-2019-0201
>= 1.0.0 and <= 3.4.13
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t ch
5.9
MEDIUM
CVE-2018-8012
< 3.4.10
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-a
7.5
HIGH
CVE-2017-5637
all versions
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if
7.5
HIGH
CVE-2016-5017
<= 3.4.8
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode synta
8.1
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin