Description
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4214-1 | zookeeper security update |
EUVD |
EUVD-2022-3562 | No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader. |
Github GHSA |
GHSA-ccqf-c5hq-77mp | Missing Authorization in Apache ZooKeeper |
Ubuntu USN |
USN-4789-1 | Apache ZooKeeper vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T00:01:04.102Z
Reserved: 2018-03-09T00:00:00.000Z
Link: CVE-2018-8012
No data.
Status : Modified
Published: 2018-05-21T19:29:00.250
Modified: 2024-11-21T04:13:05.407
Link: CVE-2018-8012
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA
Ubuntu USN