Back to Vulnerability Directory
HIGHFixed upstream

CVE-2017-5637

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU…

Technology

Apache ZooKeeper

CVSS Score

7.5 / 10.0

Affected Versions

3.4.0; 3.4.1; 3.4.2; 3.4.3

Upstream Fix

See upstream advisory

Published

October 10, 2017

OSSeva Coverage

Fixed upstream

Description

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.

Is your Apache ZooKeeper deployment affected?

If you're running 3.4.0; 3.4.1; 3.4.2; 3.4.3, you need this patch. Book a discovery call to get covered.