CVE Vulnerabilities

CVE-2026-24308

Insertion of Sensitive Information into Log File

Published: Mar 07, 2026 | Modified: Mar 10, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
3.3 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the clients logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
ZookeeperApache3.8.0 (including)3.8.6 (excluding)
ZookeeperApache3.9.0 (including)3.9.5 (excluding)

Potential Mitigations

References