Severity: moderate
Affected versions:
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.9.0 through 3.9.5
- Apache ZooKeeper (org.apache.zookeeper:zookeeper) 3.8.0 through 3.8.6
Description:
An unauthenticated attacker can inject arbitrary fake log lines into Apache
ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...)
request containing newline characters (\n). When the ensemble name doesn't
match, EnsembleAuthenticationProvider.handleAuthentication() logs the raw,
unsanitized name via LOG.warn(). Because SLF4J's {} placeholder preserves
embedded newlines, the attacker can forge complete log entries — with arbitrary
timestamps, log levels, class names, and messages — that are visually
indistinguishable from genuine ZooKeeper log output.
This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5, from 3.8.0
through 3.8.6.
Users are recommended to upgrade to version 3.8.7 or 3.9.6, which fixes the
issue.
Credit:
Youlong Chen Institute of Computing Technology <[email protected]>
(finder)
References:
https://zookeeper.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-84501