CVE-2024-51504 describes an authentication bypass vulnerability in Apache ZooKeeper's Admin Server when using IPAuthenticationProvider. This critical flaw (CVSS 9.1) allows attackers to spoof their IP address via the X-Forwarded-For header, bypassing authentication and enabling arbitrary execution of Admin Server commands like snapshot and restore, potentially leading to information leakage or service disruption. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog. Users are advised to upgrade to ZooKeeper version 3.9.3 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.9.0, < 3.9.3CPE matchmatch criteria | cpe:2.3:a:apache:zookeeper:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025
Aug 6, 2025Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
Nov 7, 2024org.apache.zookeeper: Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
Nov 7, 2024