Impact
An unauthenticated attacker can embed newline characters into an add_auth request to forge log entries. When the ensemble name does not match, the authentication provider logs the raw string via a warning call. Because SLF4J’s {} placeholder preserves newlines, the attacker may create forged log lines with arbitrary timestamps, levels, identical to genuine ZooKeeper output. This represents a log injection flaw (CWE‑117) allowing the attacker to obscure real events or inject misleading forensic data.
Affected Systems
Apache ZooKeeper versions 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5 are affected. Versions 3.8.7 and 3.9.6 contain the vendor fix.
Risk and Exploitability
The CVSS score is not provided in the data. EPSS is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack can be performed remotely by sending a crafted request and does not require elevated privileges. The impact is limited to log forgery, which can compromise forensic integrity but does not enable code execution or privilege escalation.
OpenCVE Enrichment