Improper Permission Check in Apache ZooKeeper Affects AdminServer Functionality
CVE-2025-58457
4.3MEDIUM
What is CVE-2025-58457?
The vulnerability in Apache ZooKeeper's AdminServer allows authorized clients to execute snapshot and restore commands without proper permissions. This issue poses a security risk by potentially enabling unauthorized access to sensitive functionality, which can compromise the integrity of their data management processes. Users are advised to upgrade to version 3.9.4 to address this issue or mitigate the risk by disabling the snapshot and restore commands and enforcing strict access control lists on the root ACL.
Affected Version(s)
Apache ZooKeeper 3.9.0 < 3.9.4
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Damien Diederen <[email protected]>