← back
CVE-2017-5637

CVE-2017-5637

45Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 73%
from disclosure to weapon0 days
Published on NVDOct 10
1st PoCJul 2
exploitation probability
73%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.