Apache Product Security Update Advisory

Overview

 

An update has been made available to address a vulnerability in Apache software. users of affected versions are advised to update to the latest version.

 

Affected Products

 

ZooKeeper

  • 3.versions 9.0 through 3.9.1
  • 3.versions 8.0 through 3.8.3
  • 3.versions 6.0 through 3.7.2

 

Resolved Vulnerabilities

 

Information disclosure vulnerability due to lack of ACL validation in Apache’s ZooKeeper (CVE-2024-23944) [1]

 

Vulnerability Patches

 

ZooKeeper version 3.9.2, 3.8.4

 

Referenced Sites

 

[1] ZooKeeper Security

https://zookeeper.apache.org/security.html#CVE-2024-23944

[2] Apache ZooKepper Releases

https://zookeeper.apache.org/releases.html