CVE-2017-5637

high
Published 2017-10-10 · Modified 2023-11-08
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
5.0
VIR risk
7.5

Description

Uncontrolled Resource Consumption in Apache ZooKeeper

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-5637

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — https://issues.apache.org/jira/browse/ZOOKEEPER-2693

OS impact

OSVersionStatusFixed in
debian debian8.0affected
debian debianbookwormfixed3.4.9-3
debian debianbullseyefixed3.4.9-3
debian debianforkyfixed3.4.9-3
debian debiansidfixed3.4.9-3
debian debiantrixiefixed3.4.9-3

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.zookeeper:zookeeper>=3.4.0,<3.4.103.4.10
java Mavenorg.apache.zookeeper:zookeeper>=3.5.0,<3.5.33.5.3

Application impact

VendorProductVersionsFixed
apache apachezookeeper3.4.0
apache apachezookeeper3.4.1
apache apachezookeeper3.4.2
apache apachezookeeper3.4.3
apache apachezookeeper3.4.4
apache apachezookeeper3.4.5
apache apachezookeeper3.4.6
apache apachezookeeper3.4.7
apache apachezookeeper3.4.8
apache apachezookeeper3.4.9
apache apachezookeeper3.5.0
apache apachezookeeper3.5.1
apache apachezookeeper3.5.2

References

CWEs

CWE-306 CWE-400

Verify integrity in audit chain (admin only). AS-IS.