PT-2017-4199 · Apache+2 · Apache Zookeeper+2
CVE-2017-5637
·
Publicado
2017-01-29
·
Atualizado
2024-08-15
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache ZooKeeper versions prior to 3.4.10
Apache ZooKeeper versions prior to 3.5.3
Description
The issue is related to the lack of authentication for a critical function in the implementation of the wchp/wchc command in Apache ZooKeeper, which provides configuration information, naming, distributed synchronization, and group services. This can be exploited by a remote attacker to cause a denial of service. The
wchp/wchc commands are CPU intensive and can cause a spike in CPU utilization on the Apache ZooKeeper server if abused, leading to the server being unable to serve legitimate client requests.Recommendations
For Apache ZooKeeper versions prior to 3.4.10, update to version 3.4.10 or later.
For Apache ZooKeeper versions prior to 3.5.3, update to version 3.5.3 or later.
As a temporary workaround, consider restricting access to the
wchp and wchc commands to minimize the risk of exploitation.Exploit
Correção
Missing Authentication
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Zookeeper
Red Os
Ubuntu