Impact
An unauthenticated attacker can embed newline characters into an add_auth request to forge log entries. When the ensemble name does not match, the authentication provider logs the raw string via a warning call. Because SLF4J’s {} placeholder preserves newlines, the attacker may create forged log lines with arbitrary timestamps, levels, identical to genuine ZooKeeper output. This represents a log injection flaw (CWE‑117) allowing the attacker to obscure real events or inject misleading forensic data.
Affected Systems
Apache ZooKeeper versions 3.8.0 through 3.8.6 and 3.9.0 through 3.9.5 are affected. Versions 3.8.7 and 3.9.6 contain the vendor fix.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity vulnerability. The EPSS score of less than 1% shows a low probability of exploitation, and the issue is not listed in CISA’s KEV catalog. The attacker can remotely submit a crafted add_auth("ensemble", …) request containing newline characters to forge log entries without needing authentication or elevated privileges. The impact is confined to log forgery, potentially obfuscating real events or inserting misleading forensic data, but it does not allow code execution or privilege escalation.
OpenCVE Enrichment