PT-2025-39239 · Apache+2 · Apache Zookeeper+2

Damien Diederen

·

Published

2025-09-24

·

Updated

2026-04-10

·

CVE-2025-58457

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache ZooKeeper versions 3.9.0 through 3.9.3
Description An improper permission check exists in the ZooKeeper AdminServer, allowing authorized clients to execute snapshot and restore commands with insufficient permissions. The issue can be mitigated by disabling the snapshot and restore commands via admin.snapshot.enabled and admin.restore.enabled, disabling the entire AdminServer interface via admin.enableServer, or ensuring the root Access Control List (ACL) does not provide open permissions. ZooKeeper ACLs are not recursive, meaning this does not impact operations on child nodes beyond notifications from recursive watches.
Recommendations Upgrade to version 3.9.4. Disable the snapshot and restore commands via admin.snapshot.enabled and admin.restore.enabled. Disable the AdminServer interface via admin.enableServer. Ensure the root ACL does not provide open permissions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12605
BIT-ZOOKEEPER-2025-58457
CVE-2025-58457
GHSA-2HMJ-97JW-28JH

Affected Products

Apache Zookeeper
Debian
Red Os