Impact
Apache ZooKeeper fails to enforce peer hostname verification when FIPS mode is enabled and quorum TLS settings are configured. A CA‑trusted certificate whose subject alternative name does not match the host name can be accepted, allowing a malicious or misissued peer to join the quorum. This compromised node can participate in leader election and replicate data, resulting in integrity loss and possible service disruption.
Affected Systems
The flaw affects any Apache ZooKeeper installation that enables sslQuorum, zookeeper.fips-mode, ssl.quorum.hostnameVerification, and ssl.quorum.clientHostnameVerification. All deployed versions lacking the vendor‑issued fix are vulnerable; the official fix is provided in ZooKeeper 3.8.7 and 3.9.6.
Risk and Exploitability
Based on the description, it is inferred that an attacker could exploit the vulnerability by presenting a CA‑trusted certificate with a mismatched subject alternative name to a quorum node that is running with FIPS mode enabled. The likely attack vector is over the network, as the SSL/TLS connection is negotiated between quorum members. The EPSS score of <1% indicates a very low but nonzero exploitation probability, and the CVSS score of 7.5 classifies the issue as high severity. Because the vulnerability is not listed in CISA KEV, there are no publicly released exploit packages specifically targeting this flaw, but an attacker with network access could still attempt the certificate bypass to subvert quorum membership and compromise data integrity.
OpenCVE Enrichment