GHSA-2hmj-97jw-28jh
Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Quick fix
GHSA-2hmj-97jw-28jh — org.apache.zookeeper:zookeeper: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.9.4</version> for org.apache.zookeeper:zookeeperDetails
Improper permission checks in the AdminServer allow an authenticated client with insufficient privileges to invoke the `snapshot` and `restore` commands. The intended requirement is authentication and authorization on the root path (`/`) with **ALL** permission for these operations; however, affected versions permit invocation without that level of authorization. The primary risk is disclosure of cluster state via snapshots to a lesser-privileged client.
* **Affected:** `org.apache.zookeeper:zookeeper` 3.9.0 through 3.9.3. * **Fixed:** 3.9.4 (ZOOKEEPER-4964 “check permissions individually during admin server auth”). * **Mitigations:** * Disable both commands (`admin.snapshot.enabled`, `admin.restore.enabled`). * Disable AdminServer (`admin.enableServer`). * Ensure the root ACL is not open; note that ZooKeeper ACLs are not recursive. * Upgrade to 3.9.4.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.9.0Fixed in: 3.9.4# pom.xml: bump <version>3.9.4</version> for org.apache.zookeeper:zookeeperReferences
- https://nvd.nist.gov/vuln/detail/CVE-2025-58457[ADVISORY]
- https://github.com/apache/zookeeper[PACKAGE]
- https://lists.apache.org/thread/r5yol0kkhx2fzw22pxk1ozwm3oc6yxrx[WEB]
- https://zookeeper.apache.org/doc/current/zookeeperSnapshotAndRestore.html[WEB]
- https://zookeeper.apache.org/doc/r3.9.4/releasenotes.html[WEB]
- https://zookeeper.apache.org/security.html#CVE-2025-58457[WEB]
- http://github.com/apache/zookeeper/commit/71e173fcbcc9deb784081cf867bd045df3c32635[WEB]
- http://www.openwall.com/lists/oss-security/2025/09/24/10[WEB]