Apache ZooKeeperGHSA-7cwj-j333-x7f7
Uncontrolled Resource Consumption in Apache ZooKeeper
High7.5CVE-2017-5637 · Published May 13, 2022 · updated Nov 8, 2023
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.zookeeper:zookeeper Maven | >= 3.4.0, < 3.4.10 | 3.4.10 |
| >= 3.5.0, < 3.5.3 | 3.5.3 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- CVE-2017-5637
- nvd.nist.gov/vuln/detail/CVE-2017-5637
- access.redhat.com/errata/RHSA-2017:2477
- access.redhat.com/errata/RHSA-2017:3354
- access.redhat.com/errata/RHSA-2017:3355
- issues.apache.org/jira/browse/ZOOKEEPER-2693
- lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E
- lists.apache.org/thread.html/58170aeb7a681d462b7fa31cae81110cbb749d2dc83c5736a0bb8370@%3Cdev.zookeeper.apache.org%3E
- lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E
- lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E
- www.oracle.com//security-alerts/cpujul2021.html
- www.oracle.com/security-alerts/cpujul2020.html
- www.debian.org/security/2017/dsa-3871
- www.securityfocus.com/bid/98814
More Apache ZooKeeper advisories
All Apache ZooKeeper| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 242025 | Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands | Medium4.3 | 3.9.4 |
| Nov 72024 | Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server | High | 3.9.3 |
| Mar 152024 | Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling | Medium5.3 | 3.8.4+1 more |
| Oct 112023 | Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper | Critical9.1 | 3.7.2+2 more |
| May 132022 | Missing Authorization in Apache ZooKeeper | High7.5 | 3.4.10+1 more |
| May 292019 | Access control bypass in Apache ZooKeeper | Medium5.9 | 3.4.14+1 more |