Executive brief
Apache ZooKeeper is a service used to coordinate and manage configuration for large distributed systems. A vulnerability in how it handles client settings causes sensitive information to be written into plain-text log files. If an attacker gains access to these logs, they could obtain credentials or other private configuration data, potentially leading to further unauthorized access to the production environment.
Technical details
A sensitive information disclosure vulnerability exists in Apache ZooKeeper's ZKConfig component. The software improperly handles configuration values, causing them to be recorded in client log files at the standard INFO logging level. This behavior can expose sensitive credentials or secrets stored within the client configuration to anyone with read access to the logs. The issue affects versions 3.8.0 through 3.8.5 and 3.9.0 through 3.9.4. Users are advised to upgrade to versions 3.8.6 or 3.9.5 to ensure sensitive values are properly neutralized before logging.
Affected products
- Apache ZooKeeper 3.8.0 through 3.8.5, 3.9.0 through 3.9.4
- Red Hat AMQ Broker 7.12.7, 7.13.5, 7.14.0
- Red Hat OpenShift AI 2.25
- Red Hat build of Debezium 2, 3
- Red Hat Fuse 7
- Red Hat JBoss Enterprise Application Platform 7
- Red Hat streams for Apache Kafka 2, 3
Timeline
- 2026-03-07: disclosed: Initial disclosure via Apache and Openwall mailing lists
- 2026-03-07: advisory: NVD record published
- 2026-04-23: patched: Red Hat released security advisories for affected products
References
- https://repo.maven.apache.org/maven2
- https://lists.apache.org/thread/qng3rtzv2pqkmko4rhv85jfplkyrgqdr
- http://www.openwall.com/lists/oss-security/2026/03/07/5
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/errata/RHSA-2026:14272
- https://access.redhat.com/errata/RHSA-2026:14276
- https://access.redhat.com/errata/RHSA-2026:8509