Skip to main content
EPSS 0.9%top 42%

Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server (CVE-2024-51504)

0
Critical
Published: 11/09/2024 (11/09/2024, 07:22:22 UTC)
Source: GCVE Database
Product: zookeeper

Description

Apache ZooKeeper Admin Server using IP-based authentication with the IPAuthenticationProvider is vulnerable to authentication bypass via IP address spoofing. The default configuration relies on the X-Forwarded-For HTTP header to detect client IP addresses, which can be easily spoofed by an attacker. Successful exploitation allows execution of Admin Server commands such as snapshot and restore, potentially leading to information leakage or service disruption. This vulnerability affects ZooKeeper versions from 3.9.0 up to but not including 3.9.3. An official fix is available in version 3.9.3.

Affected software

Bitnamimore threats →ghsa
zookeeper
pkg:bitnami/zookeeper
Affected versions
>=3.9.0 <3.9.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 13:06:37 UTC

Technical Analysis

CVE-2024-51504 describes an authentication bypass vulnerability in Apache ZooKeeper Admin Server when using the IPAuthenticationProvider. The default client IP detection mechanism trusts the X-Forwarded-For HTTP header, which is commonly spoofed by attackers. This flaw allows attackers to bypass IP-based authentication and execute privileged Admin Server commands like snapshot and restore. The issue is fixed in ZooKeeper version 3.9.3.

Potential Impact

An attacker can bypass IP-based authentication in the ZooKeeper Admin Server by spoofing the X-Forwarded-For HTTP header, gaining unauthorized access to administrative commands. This can lead to information leakage or disruption of service availability through arbitrary execution of commands such as snapshot and restore.

Mitigation Recommendations

Users should upgrade Apache ZooKeeper to version 3.9.3 or later, where this authentication bypass vulnerability is fixed. Until upgrading, consider disabling IP-based authentication or configuring the IPAuthenticationProvider to not trust spoofable HTTP headers like X-Forwarded-For.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BIT-zookeeper-2024-51504
Osv Schema Version
1.5.0
Aliases
["CVE-2024-51504"]
Ecosystems
["Bitnami"]
Database Specific Severity
Critical

Threat ID: 6aa005acacd9273b49ab4739

Added to database: 09/08/2026, 12:55:08 UTC

Last enriched: 09/08/2026, 13:06:37 UTC

Last updated: 09/10/2026, 19:36:48 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses