Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions.

This issue affects Apache ZooKeeper: from 3.9.0 before 3.9.4.

Users are recommended to upgrade to version 3.9.4, which fixes the issue.

The issue can be mitigated by disabling both commands (via admin.snapshot.enabled and admin.restore.enabled), disabling the whole AdminServer interface (via admin.enableServer), or ensuring that the root ACL does not provide open permissions. (Note that ZooKeeper ACLs are not recursive, so this does not impact operations on child nodes besides notifications from recursive watches.)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 24 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
Description Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 before 3.9.4. Users are recommended to upgrade to version 3.9.4, which fixes the issue. The issue can be mitigated by disabling both commands (via admin.snapshot.enabled and admin.restore.enabled), disabling the whole AdminServer interface (via admin.enableServer), or ensuring that the root ACL does not provide open permissions. (Note that ZooKeeper ACLs are not recursive, so this does not impact operations on child nodes besides notifications from recursive watches.)
Title Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Weaknesses CWE-280
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-09-24T09:29:35.824Z

Reserved: 2025-09-02T11:26:57.751Z

Link: CVE-2025-58457

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-24T10:15:28.020

Modified: 2025-09-24T10:15:28.020

Link: CVE-2025-58457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.