PT-2026-93407 · Apache · Zookeeper+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache ZooKeeper versions prior to 3.8.7
Apache ZooKeeper versions prior to 3.9.6
Description
Quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When
sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket quorum path accepts a CA-trusted peer certificate whose Subject Alternative Name (SAN) does not match the connected host. This allows a malicious or misissued peer certificate to join quorum traffic, participate in leader election, and enter replication flows.Recommendations
Upgrade to version 3.8.7.
Upgrade to version 3.9.6.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Zookeeper
Zookeeper