Miggo Logo

CVE-2023-44981: Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper

9.1

CVSS Score
3.1

Basic Information

EPSS Score
0.04999%
Published
10/11/2023
Updated
2/13/2025
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.apache.zookeeper:zookeepermaven< 3.7.23.7.2
org.apache.zookeeper:zookeepermaven>= 3.8.0, < 3.8.33.8.3
org.apache.zookeeper:zookeepermaven>= 3.9.0, < 3.9.13.9.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

*ut*oriz*tion *yp*ss T*rou** Us*r-*ontroll** K*y vuln*r**ility in *p**** ZooK**p*r. I* S*SL Quorum P**r *ut**nti**tion is *n**l** in ZooK**p*r (quorum.*ut*.*n**l*S*sl=tru*), t** *ut*oriz*tion is *on* *y v*ri*yin* t**t t** inst*n** p*rt in S*SL *ut**n

Reasoning

No *n*lysis *v*il**l*