PT-2017-4199 · Apache+2 · Apache Zookeeper+2

Published

2017-01-29

·

Updated

2024-08-15

·

CVE-2017-5637

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache ZooKeeper versions prior to 3.4.10 Apache ZooKeeper versions prior to 3.5.3
Description The issue is related to the lack of authentication for a critical function in the implementation of the wchp/wchc command in Apache ZooKeeper, which provides configuration information, naming, distributed synchronization, and group services. This can be exploited by a remote attacker to cause a denial of service. The wchp/wchc commands are CPU intensive and can cause a spike in CPU utilization on the Apache ZooKeeper server if abused, leading to the server being unable to serve legitimate client requests.
Recommendations For Apache ZooKeeper versions prior to 3.4.10, update to version 3.4.10 or later. For Apache ZooKeeper versions prior to 3.5.3, update to version 3.5.3 or later. As a temporary workaround, consider restricting access to the wchp and wchc commands to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2022-04726
CVE-2017-5637
DLA-986-1
DSA-3871-1
GHSA-7CWJ-J333-X7F7
SUSE-SU-2020:1066-1
USN-4789-1

Affected Products

Apache Zookeeper
Red Os
Ubuntu