Two four letter word commands wchp/wchc are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zookeeper | Apache | 3.4.0 (including) | 3.4.0 (including) |
Zookeeper | Apache | 3.4.1 (including) | 3.4.1 (including) |
Zookeeper | Apache | 3.4.2 (including) | 3.4.2 (including) |
Zookeeper | Apache | 3.4.3 (including) | 3.4.3 (including) |
Zookeeper | Apache | 3.4.4 (including) | 3.4.4 (including) |
Zookeeper | Apache | 3.4.5 (including) | 3.4.5 (including) |
Zookeeper | Apache | 3.4.6 (including) | 3.4.6 (including) |
Zookeeper | Apache | 3.4.7 (including) | 3.4.7 (including) |
Zookeeper | Apache | 3.4.8 (including) | 3.4.8 (including) |
Zookeeper | Apache | 3.4.9 (including) | 3.4.9 (including) |
Zookeeper | Apache | 3.5.0 (including) | 3.5.0 (including) |
Zookeeper | Apache | 3.5.1 (including) | 3.5.1 (including) |
Zookeeper | Apache | 3.5.2 (including) | 3.5.2 (including) |
Zookeeper | Ubuntu | artful | * |
Zookeeper | Ubuntu | esm-apps/xenial | * |
Zookeeper | Ubuntu | trusty | * |
Zookeeper | Ubuntu | trusty/esm | * |
Zookeeper | Ubuntu | upstream | * |
Zookeeper | Ubuntu | xenial | * |
Zookeeper | Ubuntu | yakkety | * |
Zookeeper | Ubuntu | zesty | * |
Red Hat JBoss BPMS 6.4 | RedHat | zookeeper | * |
Red Hat JBoss BRMS 6.4 | RedHat | zookeeper | * |
Red Hat JBoss Data Virtualization 6.3 | RedHat | zookeeper | * |
As data is migrated to the cloud, if access does not require authentication, it can be easier for attackers to access the data from anywhere on the Internet.