Home/Product/apache zookeeper
Product

apache zookeeper

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-24308
>= 3.8.0 and < 3.8.6
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to e
7.5HIGH
CVE-2026-24281
>= 3.8.0 and < 3.8.6
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing at
7.4HIGH
CVE-2025-58457
>= 3.9.0 and < 3.9.4
Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient p
4.3MEDIUM
CVE-2024-51504
>= 3.9.0 and < 3.9.3
When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this
9.1CRITICAL
CVE-2024-23944
>= 3.6.0 and <= 3.7.2
Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to moni
5.3MEDIUM
CVE-2023-44981
< 3.7.2
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled
9.1CRITICAL
CVE-2021-21295
all versions
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high perfor
5.9MEDIUM
CVE-2019-0201
>= 1.0.0 and <= 3.4.13
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t ch
5.9MEDIUM
CVE-2018-8012
< 3.4.10
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-a
7.5HIGH
CVE-2017-5637
all versions
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if
7.5HIGH
CVE-2016-5017
<= 3.4.8
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode synta
8.1HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin