Severity: important 

Affected versions:

- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.4
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.5

Description:

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 
and 3.9.4 on all platforms allows an attacker to expose sensitive information 
stored in client configuration in the client's logfile. Configuration values 
are exposed at INFO level logging rendering potential production systems 
affected by the issue. Users are recommended to upgrade to version 3.8.6 or 
3.9.5 which fixes this issue.

Credit:

Youlong Chen <[email protected]> (reporter)

References:

https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-24308

Reply via email to