Vulnerability record · CVE-2023-44981 · published 11 October 2023
CVE-2023-44981: Apache zookeeper insecure direct object reference vulnerability
Apache · Zookeeper
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like '[email protected]', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default. Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue. Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue. See the documentation for more details on correct cluster administration.
Description
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in zoo.cfg server list. The instance part in SASL auth ID is optional and if it's missing, like '[email protected]', the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. Quorum Peer authentication is not enabled by default. Users are recommended to upgrade to version 3.9.1, 3.8.3, 3.7.2, which fixes the issue. Alternately ensure the ensemble election/quorum communication is protected by a firewall as this will mitigate the issue. See the documentation for more details on correct cluster administration.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2023/10/11/4 | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/wf0yrk84dg1942z1o74kd8nycg6pgm5b | Issue TrackingVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/10/msg00029.html | Mailing List |
| https://security.netapp.com/advisory/ntap-20240621-0007/ | |
| https://www.debian.org/security/2023/dsa-5544 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2023/10/11/4 | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/wf0yrk84dg1942z1o74kd8nycg6pgm5b | Issue TrackingVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/10/msg00029.html | Mailing List |
| https://security.netapp.com/advisory/ntap-20240621-0007/ | |
| https://www.debian.org/security/2023/dsa-5544 | Mailing ListThird Party Advisory |
Track CVE-2023-44981 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-44981), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.