VDB
Sign up
MEDIUM4.3

GHSA-2hmj-97jw-28jh

Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands

Quick fix

GHSA-2hmj-97jw-28jh — org.apache.zookeeper:zookeeper: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.9.4</version> for org.apache.zookeeper:zookeeper

Details

Improper permission checks in the AdminServer allow an authenticated client with insufficient privileges to invoke the `snapshot` and `restore` commands. The intended requirement is authentication and authorization on the root path (`/`) with **ALL** permission for these operations; however, affected versions permit invocation without that level of authorization. The primary risk is disclosure of cluster state via snapshots to a lesser-privileged client.

* **Affected:** `org.apache.zookeeper:zookeeper` 3.9.0 through 3.9.3. * **Fixed:** 3.9.4 (ZOOKEEPER-4964 “check permissions individually during admin server auth”). * **Mitigations:** * Disable both commands (`admin.snapshot.enabled`, `admin.restore.enabled`). * Disable AdminServer (`admin.enableServer`). * Ensure the root ACL is not open; note that ZooKeeper ACLs are not recursive. * Upgrade to 3.9.4.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.zookeeper:zookeeper
Introduced in: 3.9.0Fixed in: 3.9.4
Fix# pom.xml: bump <version>3.9.4</version> for org.apache.zookeeper:zookeeper

References