Record summary

CVE-2017-5637 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List3.4.0 to 3.4.9affected
3.5.0 to 3.5.2affected

org.apache.zookeeper:zookeeper

Browse Maven / org.apache.zookeeper:zookeeper
GitHub Advisory3.4.0 to < 3.4.10 · Fixed in 3.4.10affected
3.5.0 to < 3.5.3 · Fixed in 3.5.3affected

Proofs of concept

1

Catalogued exploits

ExploitDBZookeeper 3.5.2 Client - Denial of ServiceExploitDB exploitby Brandon DennisNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 17