CVE detail
CVE-2026-24308
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24308.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 7, 2026, 9:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2445451bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/security/cve/CVE-2026-24308access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:8509access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:34608access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:14276access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:14272access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - https://access.redhat.com/errata/RHSA-2026:10184access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 7, 2026, 9:16 AM - http://www.openwall.com/lists/oss-security/2026/03/07/5www.openwall.com
No excerpt available.
Exploitwww.openwall.comMar 7, 2026, 9:16 AM - https://lists.apache.org/thread/qng3rtzv2pqkmko4rhv85jfplkyrgqdrlists.apache.org
No excerpt available.
Vendor Advisorylists.apache.orgMar 7, 2026, 9:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-45679CVSS 6.5 · Medium
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status m…
- CVE-2025-49846CVSS 4.1 · Medium
wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages that were visible in the view port have been logged to the i…
- CVE-2024-47083CVSS 8.8 · High
Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Pro…
- CVE-2020-14332CVSS 5.5 · Medium
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive data exposed in the event data. T…
- CVE-2019-14854CVSS 6.5 · Medium
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user cou…
- CVE-2019-14864CVSS 6.5 · Medium
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callb…