REDHAT-BUG-1454808: Medium severity apache zookeeper vulnerability
Two four letter word commands “wchp/wchc” are CPU intensive and could cause spike of CPU utilization on ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests.
Upstream issue:
https://issues.apache.org/jira/browse/ZOOKEEPER-2693
References:
https://vulners.com/exploitdb/EDB-ID:41277
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1454808?
The severity of REDHAT-BUG-1454808 is considered high due to its potential to cause CPU spikes impacting ZooKeeper server functionality.
What are the potential impacts of REDHAT-BUG-1454808?
REDHAT-BUG-1454808 can lead to the ZooKeeper server becoming unresponsive, causing legitimate client requests to fail.
How do I mitigate the effects of REDHAT-BUG-1454808?
To mitigate REDHAT-BUG-1454808, consider implementing rate limiting or access controls to prevent abuse of the CPU-intensive commands.
What versions of ZooKeeper are affected by REDHAT-BUG-1454808?
REDHAT-BUG-1454808 affects specific versions of Apache ZooKeeper, particularly those that allow the use of the commands 'wchp' and 'wchc'.
Is there a fix available for REDHAT-BUG-1454808?
At this time, there may not be a dedicated fix for REDHAT-BUG-1454808, and it is advisable to monitor for upstream updates or patches.