Skip to content

H3-2020-0002

Anonymous Access to ZooKeeper API

Category SECURITY_MISCONFIGURATION
Base Score 5.0

Description

The ZooKeeper API accepts anonymous connections.

Impact

Attackers could perform denial-of-service (DoS) attacks by killing services or uploading large files to fill up the filesystem.

References