CVE-2017-5637
published 2017-10-10CVE-2017-5637: Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the…
PriorityP269high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EXPLOIT
EPSS
73.65%
99.4th percentile
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | >= 0 < 3.4.9-3 | 3.4.9-3 |
| apache | zookeeper | >= 0 < 3.4.9-3 | 3.4.9-3 |
| apache | zookeeper | >= 0 < 3.4.9-3 | 3.4.9-3 |
| apache | zookeeper | >= 0 < 3.4.9-3 | 3.4.9-3 |
| apache | zookeeper | >= 0 < 3.4.5+dfsg-1ubuntu0.1~esm1 | 3.4.5+dfsg-1ubuntu0.1~esm1 |
| apache | zookeeper | >= 0 < 3.4.8-1ubuntu0.1~esm1 | 3.4.8-1ubuntu0.1~esm1 |
| apache_software_foundation | apache_zookeeper | — | — |
| apache_software_foundation | apache_zookeeper | — | — |
| debian | debian_linux | — | — |
| debian | zookeeper | < zookeeper 3.4.9-3 (bookworm) | zookeeper 3.4.9-3 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Alert on sudden CPU spikes (90-100%) on ZooKeeper servers correlated with a large number of concurrent TCP connections to port 2181, which may indicate exploitation via repeated wchp/wchc commands. ↗
- →Detect TCP streams to port 2181 containing the raw byte sequences for 'wchp ' or 'wchc ' as payload, which are the exact strings sent by the exploit. ↗
- ·The exploit targets ZooKeeper versions 3.x and above through 3.4.9 and 3.5.2; versions 3.4.10, 3.5.3, and later are fixed. Ensure ZooKeeper is upgraded or that 'wchp'/'wchc' four-letter commands are disabled/firewalled on port 2181. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv8.1HIGH
vendor_ubuntu8.1HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Uncontrolled Resource Consumption in Apache ZooKeeper
ghsa·2022-05-13
CVE-2017-5637 [HIGH] CWE-400 Uncontrolled Resource Consumption in Apache ZooKeeper
Uncontrolled Resource Consumption in Apache ZooKeeper
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
OSV
Uncontrolled Resource Consumption in Apache ZooKeeper
osv·2022-05-13
CVE-2017-5637 [HIGH] Uncontrolled Resource Consumption in Apache ZooKeeper
Uncontrolled Resource Consumption in Apache ZooKeeper
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
OSV
zookeeper vulnerabilities
osv·2021-03-15·CVSS 8.1
CVE-2016-5017 [HIGH] zookeeper vulnerabilities
zookeeper vulnerabilities
It was discovered that Apache ZooKeeper incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2016-5017)
It was discovered that Apache ZooKeeper incorrectly implemented "wchp/wchc"
commands. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-5637)
It was discovered that Apache Zookeeper incorrectly handled clusters. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected Ubuntu 16.04 ESM. (CVE-2018-8012)
OSV
CVE-2017-5637: Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads
osv·2017-10-10·CVSS 7.5
CVE-2017-5637 [HIGH] CVE-2017-5637: Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Cloud Gateway (Zookeeper) — CVE-2017-5637
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2017-5637 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: Cloud Gateway (Zookeeper) — CVE-2017-5637
Oracle Oracle Siebel CRM Risk Matrix: Cloud Gateway (Zookeeper) vulnerability
CVE: CVE-2017-5637
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Ubuntu
Apache ZooKeeper vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 8.1
CVE-2017-5637 [HIGH] Apache ZooKeeper vulnerabilities
Title: Apache ZooKeeper vulnerabilities
Summary: Several security issues were fixed in Apache ZooKeeper.
It was discovered that Apache ZooKeeper incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2016-5017)
It was discovered that Apache ZooKeeper incorrectly implemented "wchp/wchc"
commands. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-5637)
It was discovered that Apache Zookeeper incorrectly handled clusters. An
attacker could possibly use this issue to obtain sensitive information.
This issue was only fixed in Ubuntu 16.04 ESM. (CVE-2018-8012)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
zookeeper: Incorrect input validation with wchp/wchc four letter words
vendor_redhat·2017-02-07·CVSS 7.5
CVE-2017-5637 [HIGH] CWE-20 zookeeper: Incorrect input validation with wchp/wchc four letter words
zookeeper: Incorrect input validation with wchp/wchc four letter words
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
A denial of service vulnerability was discovered in ZooKeeper which allows an attacker to dramatically increase CPU utilization by abusing "wchp/wchc" commands, leading to the server being unable to serve legitimate requests.
Package: zookeeper (Red Hat JBoss A-MQ 6) - Will not fix
Package: zookeeper (Red Hat JBoss Fuse 6) - Will not fix
Package: zookeeper (Red Hat OpenShift Enterprise 2) - Under investigat
Debian
CVE-2017-5637: zookeeper - Two four letter word commands "wchp/wchc" are CPU intensive and could cause spik...
vendor_debian·2017·CVSS 7.5
CVE-2017-5637 [HIGH] CVE-2017-5637: zookeeper - Two four letter word commands "wchp/wchc" are CPU intensive and could cause spik...
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
Scope: local
bookworm: resolved (fixed in 3.4.9-3)
bullseye: resolved (fixed in 3.4.9-3)
forky: resolved (fixed in 3.4.9-3)
sid: resolved (fixed in 3.4.9-3)
trixie: resolved (fixed in 3.4.9-3)
No detection rules found.
Bugzilla
CVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter words [fedora-all]
bugzilla·2017-05-23·CVSS 7.5
CVE-2017-5637 [HIGH] CVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter words [fedora-all]
CVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter words [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter words
bugzilla·2017-05-23·CVSS 7.5
CVE-2017-5637 [HIGH] CVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter words
CVE-2017-5637 zookeeper: Incorrect input validation with wchp/wchc four letter words
Two four letter word commands “wchp/wchc” are CPU intensive and could cause spike of CPU utilization on ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests.
Upstream issue:
https://issues.apache.org/jira/browse/ZOOKEEPER-2693
References:
https://vulners.com/exploitdb/EDB-ID:41277
Discussion:
Created zookeeper tracking bugs for this issue:
Affects: fedora-all [bug 1454809]
---
taking
---
For fuse the recommended security practice to mitigate this issue is to deploy and operate zookeeper in a secured network where essentially the affected port are protected by the firewall. Additionally it should be assumed that only admin has access to the affected po
http://www.debian.org/security/2017/dsa-3871http://www.securityfocus.com/bid/98814https://access.redhat.com/errata/RHSA-2017:2477https://access.redhat.com/errata/RHSA-2017:3354https://access.redhat.com/errata/RHSA-2017:3355https://issues.apache.org/jira/browse/ZOOKEEPER-2693https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/58170aeb7a681d462b7fa31cae81110cbb749d2dc83c5736a0bb8370%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttp://www.debian.org/security/2017/dsa-3871http://www.securityfocus.com/bid/98814https://access.redhat.com/errata/RHSA-2017:2477https://access.redhat.com/errata/RHSA-2017:3354https://access.redhat.com/errata/RHSA-2017:3355https://issues.apache.org/jira/browse/ZOOKEEPER-2693https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/58170aeb7a681d462b7fa31cae81110cbb749d2dc83c5736a0bb8370%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.html
2017-10-10
Published