# Security Advisory: CVE-2023-44981 Apache ZooKeeper™

[Blog](/blog/)&gt;[Technical](/blog/category/technical/)&gt;Security Advisory: CVE-2023-44981 Apache ZooKeeper™ 

Security Advisory: CVE-2023-44981 Apache ZooKeeper™
===================================================

October 24, 2023 | By [ Instaclustr ](https://www.instaclustr.com/blog/author/instaclustr/)

 

 

 

 



   [ ](https://x.com/intent/tweet?text=Security%20Advisory:%20CVE-2023-44981%20Apache%20ZooKeeper%E2%84%A2&url=https://www.instaclustr.com/blog/security-advisory-cve-2023-44981-apache-zookeeper/) [ ](https://www.linkedin.com/shareArticle?mini=true&url=https://www.instaclustr.com/blog/security-advisory-cve-2023-44981-apache-zookeeper/&title=&summary=Security%20Advisory:%20CVE-2023-44981%20Apache%20ZooKeeper%E2%84%A2&source=) 

Issue Details: 
---------------

On [October 11, 2023](https://www.cve.org/CVERecord?id=CVE-2023-44981), the Apache ZooKeeper™ project [announced](https://zookeeper.apache.org/security.html#CVE-2023-44981) that a security vulnerability has been identified in Apache ZooKeeper, [CVE-2023-44981.](https://nvd.nist.gov/vuln/detail/CVE-2023-44981) The Apache ZooKeeper project has classified the severity of this CVE as critical. The CVSS (Common Vulnerability Scoring System) 3.x severity rating for this vulnerability by the NVD (National Vulnerability Database) is base score 9.1 Critical.

When considered in the context of the standard security controls implemented by Instaclustr’s Managed Platform, we have assessed the residual risk as **Low.**

This vulnerability applies to Apache ZooKeeper version 3.9.0, version 3.8.0 through 3.8.2, version 3.7.0 through 3.7.1, and Apache ZooKeeper before 3.7.0.

When SASL Quorum Peer authentication is set to True (quorum.auth.enableSasl= true), the authorization check is done by verifying that the FQDN (Fully Qualified Domain Name) in the SASL authentication ID of the incoming request is listed in the known servers list in zoo.cfg of the Quorum server. However, this part is optional in SASL authentication ID, and when it is not specified the authorization check is skipped. This could lead to unauthorized access to the data tree and result in any arbitrary endpoint joining the cluster and making changes to the leader. By default, Quorum Peer Authentication is not enabled.

Impact Analysis: 
-----------------

Instaclustr performed an investigation into this vulnerability and its potential impact on customers of our Managed Kafka and Managed ZooKeeper services, and assessed its severity rating in the Instaclustr environment as **Low**. The finding is itemized below:

- Quorum Peer authentication is not enabled by default, and Instaclustr has not explicitly enabled this. Therefore, our Managed Kafka clusters (with Colocated ZooKeeper or Dedicated ZooKeeper) and Managed ZooKeeper clusters are not affected.

Mitigation Approaches: 
-----------------------

Based on the impact detailed above, Instaclustr recommends the following actions for our customers:

- **Managed Service Customers**:    
    (Customers using colocated, dedicated, or managed ZooKeeper)   
    Based on the investigation, we believe that our managed service customers do not need to take any immediate action to mitigate this vulnerability. This CVE does not impact our Managed Kafka or Managed ZooKeeper clusters because the Quorum Peer authentication is not enabled by default and not explicitly enabled by Instaclustr.
- **Support Only Customers**:    
    For support only customers, first we recommend checking if Quorum Peer authentication is enabled. This can be done by going to the version of ZooKeeper that is being used and checking zoo.cfg file. Then look for “quorum.auth.enableSasl=” field. If this is not present, no further action is required. If it is true, we recommend the following actions: 
    - Ensure the ensemble election/Quorum communication is protected by a firewall. This mitigates the risk. Reach out to [Instaclustr Support team](https://support.instaclustr.com/hc/en-us?_gl=1*1ikppky*_ga*MTgyMDk0NzgwMi4xNjc3MTE0Mjc1*_ga_4NBQSJMP6D*MTY5NzUyMjA0NC44MC4xLjE2OTc1MjIwNTkuNDUuMC4w&_ga=2.258934862.550465082.1697522046-1820947802.1677114275) for help.
    - Upgrade to version 3.9.1, 3.8.3, or 3.7.2 which are all versions of ZooKeeper containing a fix for this issue.

Contact [Instaclustr Support](https://support.instaclustr.com/hc/en-us?_gl=1*1ikppky*_ga*MTgyMDk0NzgwMi4xNjc3MTE0Mjc1*_ga_4NBQSJMP6D*MTY5NzUyMjA0NC44MC4xLjE2OTc1MjIwNTkuNDUuMC4w&_ga=2.258934862.550465082.1697522046-1820947802.1677114275) with any further questions regarding this vulnerability and its relation to Instaclustr for Apache ZooKeeper.

 



 

 ![mail icon]()#### Get the latest articles for open sourceIn your inbox

 <a class="btn btn-primary btn-popup text-dark" href="">Sign up now</a> 

 

 

 

  ### Related content

 [ Zero Downtime Migration to Instaclustr 

 

 Yes, we can migrate existing Cassandra clusters to Instaclustr without any downtime. Here's what to expect from the process... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/zero-downtime-migration-to-instaclustr/) 

 [ Workflow Comparison: Uber Cadence vs Netflix Conductor 

 

 When choosing what’s right for your company’s opensource workflow needs it is important to know the difference and similarities ... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/workflow-comparison-uber-cadence-vs-netflix-conductor/) 

 [ Will Your Cassandra Database Project Succeed?: The New Stack 

 

 Open source Apache Cassandra® continues to stand out as an enterprise-proven solution for organizations seeking high availability... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/will-your-cassandra-database-project-succeed-the-new-stack/) 

 

  <a class="close-modal" href="">×</a>Sign upto ourNewsletter
-----------------------
