H3-2020-0002
Anonymous Access to ZooKeeper API
Category | SECURITY_MISCONFIGURATION |
Base Score | 5.0 |
Description
The ZooKeeper API accepts anonymous connections.
Impact
Attackers could perform denial-of-service (DoS) attacks by killing services or uploading large files to fill up the filesystem.