https://seclists.org/oss-sec/2024/q1/229: CVE-2024-23944: Apache ZooKeeper: Information disclosure in persistent watcher handling
Published Mar 14, 2024
·Updated
Affected Software
1 affected component
Apache Zookeeper
Frequently Asked Questions
1
What is the severity of CVE-2024-23944?
CVE-2024-23944 has been classified as a moderate severity vulnerability due to its potential for information disclosure.
2
How does CVE-2024-23944 impact Apache ZooKeeper users?
CVE-2024-23944 allows unauthorized access to sensitive information through persistent watcher handling, posing a risk to user data.
3
How do I fix CVE-2024-23944?
To mitigate CVE-2024-23944, users should upgrade to the latest patched version of Apache ZooKeeper.
4
Which versions of Apache ZooKeeper are affected by CVE-2024-23944?
CVE-2024-23944 affects multiple versions of Apache ZooKeeper prior to the security fix released on March 14, 2024.
5
Are there any workarounds for CVE-2024-23944?
There are no specific workarounds for CVE-2024-23944; upgrading to a fixed version is recommended.