Apache ZooKeeper Flaw Exposes Sensitive Data to Attackers
ID: a88f638f-0fe3-57da-bdbc-172c1a6c93da
STIX ID: report--a88f638f-0fe3-57da-bdbc-172c1a6c93da
Feed Name: GBHackers
Threat Score
Apache ZooKeeper released fixes for two Important vulnerabilities: CVE-2026-24308, which can expose sensitive configuration values by logging them at INFO level, and CVE-2026-24281, a hostname verification bypass caused by reverse-DNS (PTR) fallback; both affect 3.8.0–3.8.5 and 3.9.0–3.9.4 — administrators are advised to upgrade to 3.8.6 or 3.9.5, audit past logs for leaked credentials, and rotate any exposed secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
