CVE-2024-23944
Severity
5.3MEDIUM
EPSS
0.0%
top 95.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 15
Latest updateOct 15
Description
Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a persistent watcher (addWatch command) to a parent which the attacker has already access to. ZooKeeper server doesn't do ACL check when the persistent watcher is triggered and as a consequence, the full path of znodes that a watch event gets triggered upon is exposed to the owner of the watcher. It's important to note that only the path …
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4
Affected Packages4 packages
🔴Vulnerability Details
4OSV
▶
OSV▶
CVE-2024-23944: Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check↗2024-03-15
GHSA
▶
📋Vendor Advisories
4Oracle▶
Oracle Oracle Construction and Engineering Risk Matrix: Document Management (Apache ZooKeeper) — CVE-2024-23944↗2024-07-15
Red Hat▶
Apache-ZooKeeper: Apache ZooKeeper: Information disclosure in persistent watcher handling↗2024-03-15
Debian▶
CVE-2024-23944: zookeeper - Information disclosure in persistent watchers handling in Apache ZooKeeper due t...↗2024