Impact
The deleteContainer operation is processed without verifying the caller’s ACL permissions, enabling any client that can communicate over ZooKeeper’s client port to delete znode entries that otherwise would be protected, including empty persistent, container, and TTL nodes. The bug is an authorization bypass that removes the normal session and DELETE ACL checks enforced by the ordinary delete command. An attacker can therefore compromise the configuration and integrity of the ZooKeeper data tree, potentially disrupting services that rely on ZooKeeper for coordination or metadata storage.
Affected Systems
Apache ZooKeeper versions 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5 are affected. The issue has been fixed in 3.8.7 and 3..
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score of less than 1% suggests the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploitation. Nevertheless, because the exploit does not require authentication and can be performed by opening a plain TCP session to port 2181, the potential impact on confidentiality, integrity, and availability remains significant if the ZooKeeper service is exposed.
OpenCVE Enrichment