Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 before 3.9.4. Users are recommended to upgrade to version 3.9.4, which fixes the issue. The issue can be mitigated by disabling both commands (via admin.snapshot.enabled and admin.restore.enabled), disabling the whole AdminServer interface (via admin.enableServer), or ensuring that the root ACL does not provide open permissions. (Note that ZooKeeper ACLs are not recursive, so this does not impact operations on child nodes besides notifications from recursive watches.)
History

Thu, 25 Sep 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache zookeeper
Vendors & Products Apache
Apache zookeeper

Thu, 25 Sep 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 24 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
Description Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 before 3.9.4. Users are recommended to upgrade to version 3.9.4, which fixes the issue. The issue can be mitigated by disabling both commands (via admin.snapshot.enabled and admin.restore.enabled), disabling the whole AdminServer interface (via admin.enableServer), or ensuring that the root ACL does not provide open permissions. (Note that ZooKeeper ACLs are not recursive, so this does not impact operations on child nodes besides notifications from recursive watches.)
Title Apache ZooKeeper: Insufficient Permission Check in AdminServer Snapshot/Restore Commands
Weaknesses CWE-280
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-09-24T09:29:35.824Z

Updated: 2025-09-24T13:47:35.211Z

Reserved: 2025-09-02T11:26:57.751Z

Link: CVE-2025-58457

cve-icon Vulnrichment

Updated: 2025-09-24T13:47:24.244Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-24T10:15:28.020

Modified: 2025-09-24T18:11:24.520

Link: CVE-2025-58457

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-09-24T09:29:35Z

Links: CVE-2025-58457 - Bugzilla