GHSA-r978-9m6m-6gm6

    Dashboard / Vulnerabilities / GHSA-r978-9m6m-6gm6

    GHSA-r978-9m6m-6gm6

    Published: 15 Mar 2024Last Modified: 10 Sept 2026

    Summary: Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling

    Details: Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which the attacker has already access to. ZooKeeper server doesn't do ACL check when the persistent watcher is triggered and as a consequence, the full path of znodes that a watch event gets triggered upon is exposed to the owner of the watcher. It's important to note that only the path is exposed by this vulnerability, not the data of znode, but since znode path can contain sensitive information like user name or login ID, this issue is potentially critical. Users are recommended to upgrade to version 3.9.2, 3.8.4 which fixes the issue.

    Affected packages

    Package

    Name: org.apache.zookeeper:zookeeper

    Purl: pkg:maven/org.apache.zookeeper/zookeeper

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.8.0
    Fixed -3.8.4

    Affected versions

    3.8.0
    3.8.1
    3.8.2
    3.8.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-r978-9m6m-6gm6 | CVE-DB