Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-8012

Опубликовано: 21 мая 2018
Источник: debian
EPSS Низкий

Описание

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zookeeperfixed3.4.10-2package
zookeeperignoredwheezypackage

Примечания

  • https://issues.apache.org/jira/browse/ZOOKEEPER-1045

  • https://www.openwall.com/lists/oss-security/2018/05/21/6

  • https://cwiki.apache.org/confluence/display/ZOOKEEPER/Server-Server+mutual+authentication

  • https://issues.apache.org/jira/secure/attachment/12840904/ZOOKEEPER-1045-br-3-4.patch

EPSS

Процентиль: 68%
0.00589
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

CVSS3: 7.4
redhat
около 7 лет назад

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

CVSS3: 7.5
nvd
около 7 лет назад

No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

CVSS3: 7.5
github
около 3 лет назад

Missing Authorization in Apache ZooKeeper

CVSS3: 7.5
fstec
около 7 лет назад

Уязвимость централизованной службы для поддержки информации о конфигурации, именования, обеспечения распределенной синхронизации и предоставления групповых служб Apache ZooKeeper, позволяющая нарушителю записать произвольные файлы в операционной системе уязвимого устройства

EPSS

Процентиль: 68%
0.00589
Низкий